# Ruby on Rails ActiveStorage RCE flaw has public PoC

Published: 2026-08-03 · Severity: high
Canonical: https://vorant.io/reports/98b22900-e611-5bd3-bc78-9c71ba21510b/ruby-on-rails-activestorage-rce-flaw-has-public-poc

> A critical Ruby on Rails ActiveStorage vulnerability (CVE-2026-66066) allows unauthenticated file read and remote code execution, with a public PoC now available.

CERT-FR's weekly bulletin highlights CVE-2026-66066, a vulnerability in Ruby on Rails' ActiveStorage component that was patched on 29 July 2026. The flaw allows an unauthenticated attacker to perform arbitrary file reads and achieve remote code execution through variant processing, making it a serious threat to any exposed Rails application relying on ActiveStorage.

On 31 July 2026, the Rails maintainers confirmed the existence of a public proof-of-concept exploit and released forensic guidance and tooling to help administrators determine whether their applications are vulnerable and to search for indicators of exfiltration. The availability of a working PoC combined with unauthenticated RCE capability significantly raises the urgency for organizations running affected Rails deployments to apply the patch immediately and review logs for signs of compromise.

## Mentioned in this report

- Vulnerabilities: CVE-2026-66066

Source reporting: https://www.cert.ssi.gouv.fr/actualite/CERTFR-2026-ACT-033

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/98b22900-e611-5bd3-bc78-9c71ba21510b/ruby-on-rails-activestorage-rce-flaw-has-public-poc.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
