VDB
CVE-2026-66066
CVE-2026-66066
PUBLISHED
Ruby on Rails ist ein in der Programmiersprache Ruby geschriebenes und quelloffenes Web Application Framework.
EPSS 2.10% · 81.0th percentile
Risk Scores
EPSS Score
2.10%
81.0th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Open Source | Open Source Ruby on Rails libvips <8.13 | |
| Open Source | Open Source Ruby on Rails <7.2.3.2 | |
| Open Source | Open Source Ruby on Rails <8.1.3.1 | |
| Cloudflare | access | |
| Azure | storage | |
| AWS | config | |
| Open Source | Open Source Ruby on Rails <8.0.5.1 |
Timeline
- CVE Published
- Jul 29, 2026 VulnCheck XDB Entry
- Jul 31, 2026 Coalition ESS Score
- Jul 31, 2026 Security Advisory
- Jul 31, 2026 VulnCheck XDB Entry
- Aug 3, 2026 VulnCheck XDB Entry
- Aug 4, 2026 VulnCheck XDB Entry
- Aug 7, 2026 EPSS Score
- Aug 24, 2026 EPSS Score
- Aug 25, 2026 VulnCheck KEV Exploitation
- Aug 26, 2026 EPSS Score
- Aug 31, 2026 VulnCheck KEV Exploitation
References
- https://github.com/rapid7/metasploit-framework/pull/21733 fix
- What is CVE-2026-66066? Protecting Your Rails App from Active Storage RCE third-party-analysis
- Blog third-party-analysis
- https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2574.json advisory
- https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2574 advisory
- https://discuss.rubyonrails.org/t/cve-2026-66066-possible-arbitrary-file-read-and-remote-code-execution-in-active-storage-variant-processing/91432 advisory
- https://rubyonrails.org/2026/7/29/Rails-Versions-7-2-3-2-8-0-5-1-and-8-1-3-1-have-been-released advisory
- https://github.com/rails/rails/security/advisories/GHSA-xr9x-r78c-5hrm advisory