CVE-2026-67180: Google Turbinia arbitrary command execution
Published Aug 11, 2026
·Updated
Google Turbinia allows arbitrary command execution via worker tasks. An attacker with privileges to submit a processing request or influence an evidence path/name obtains code execution on the worker fleet. Fixed on 2026-07-10.
Affected Software
1 affected component
Google Turbinia
Event History
Aug 11, 2026
CVE Published
via MITRE·03:56 PM
Data Sourced
via MITRE·03:56 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-67180?
The severity of CVE-2026-67180 is high, with a score of 8.4.
2
How do I fix CVE-2026-67180?
To fix CVE-2026-67180, upgrade Google Turbinia to the version released on or after 2026-07-10.
3
What type of vulnerability is CVE-2026-67180?
CVE-2026-67180 is classified as an OS Command Injection vulnerability.
4
What are the consequences of exploiting CVE-2026-67180?
Exploiting CVE-2026-67180 allows an attacker to execute arbitrary commands on the worker fleet.
5
When was CVE-2026-67180 published?
CVE-2026-67180 was published on August 11, 2026.