All intelligence
// vulnerability record
cached · NVD via COSMOS syncCVE-2026-67180
HIGHpublished 2026-08-11 16:17 UTC · 1 day ago
7.5
CVSS / 10
// description
Google Turbinia allows arbitrary command execution via worker tasks. An attacker with privileges to submit a processing request or influence an evidence path/name obtains code execution on the worker fleet. Fixed on 2026-07-10.
// weaknesses (CWE)
- CWE-78