Skip to content
Critical RCE Vulnerability in Rails Active Storage Disclosed

Critical RCE Vulnerability in Rails Active Storage Disclosed

First seen 30 Jul 2026, 15:40 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster July 30, 2026 at 22:28 UTC
  • CVE-2026-66066 is a critical RCE vulnerability affecting Rails Active Storage.
  • The flaw allows unauthenticated attackers to read arbitrary files on the server.
  • Patches are available in specific Rails versions; users must upgrade to secure their applications.

On July 29, 2026, the Ruby on Rails security team published CVE-2026-66066, a critical arbitrary file read and remote code execution (RCE) vulnerability in Active Storage. Discovered by the Ethiack research team, this flaw affects default configurations of Rails 6.x, 7.x, and 8.x that utilize the vips image processor. Attackers can exploit this vulnerability to read arbitrary files on the server, including sensitive credentials, without authentication in certain setups. The vulnerability has been assigned a CVSS score of 9.5 and affects an estimated 500,000+ sites. Fixes were released in Rails versions 7.2.3.2, 8.0.5.1, and 8.1.3.1. Users are advised to upgrade immediately to mitigate the risk. The vulnerability is particularly concerning due to the widespread use of Active Storage in production applications.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 45d ago How this analysis works

Timeline

2026-07-29
CVE-2026-66066 published
Ruby on Rails disclosed a critical RCE vulnerability in Active Storage affecting versions 6.x to 8.x.
Herodevs
2026-07-29
Vulnerability discovered by Ethiack
The Ethiack research team reported the critical flaw, named KindaRails2Shell, affecting default Rails configurations.
Ethiack
2026-07-30
Patches released for affected Rails versions
Rails released updates in versions 7.2.3.2, 8.0.5.1, and 8.1.3.1 to address the vulnerability.
Herodevs

More articles in this cluster (16)

Following this threat?

Track Debian and CVE-2026-64645 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed