# Rails ActiveStorage flaw enables RCE

Published: 2026-07-30 · Severity: high · Sectors: technology
Canonical: https://vorant.io/reports/b446a846-211e-5787-b684-023a64b70d17/rails-activestorage-flaw-enables-rce

> A vulnerability in Ruby on Rails ActiveStorage variant processing allows remote code execution and arbitrary file read.

CERT-FR issued an advisory for a vulnerability in Ruby on Rails' ActiveStorage component, tracked as CVE-2026-66066. The flaw resides in ActiveStorage's variant processing functionality and can be exploited to achieve arbitrary file read and remote code execution, impacting confidentiality of data on affected systems.

Affected versions include activestorage 8.0.x prior to 8.0.5.1, 8.1.x prior to 8.1.3.1, and versions prior to 7.2.3.2. The Rails project published a security bulletin on July 29, 2026 detailing the issue. Administrators are advised to apply the vendor's patches as referenced in the official Rails security advisory.

## Mentioned in this report

- Vulnerabilities: CVE-2026-66066

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0948

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/b446a846-211e-5787-b684-023a64b70d17/rails-activestorage-flaw-enables-rce.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
