VORANT. Threat Intelligence Sign in Get the full feed

Rails ActiveStorage flaw enables RCE

high vulnerability technology

A vulnerability in Ruby on Rails ActiveStorage variant processing allows remote code execution and arbitrary file read.

CERT-FR issued an advisory for a vulnerability in Ruby on Rails' ActiveStorage component, tracked as CVE-2026-66066. The flaw resides in ActiveStorage's variant processing functionality and can be exploited to achieve arbitrary file read and remote code execution, impacting confidentiality of data on affected systems.

Affected versions include activestorage 8.0.x prior to 8.0.5.1, 8.1.x prior to 8.1.3.1, and versions prior to 7.2.3.2. The Rails project published a security bulletin on July 29, 2026 detailing the issue. Administrators are advised to apply the vendor's patches as referenced in the official Rails security advisory.

Mentioned in this report

Vulnerabilities CVE-2026-66066

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0948

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free