Critical RCE Vulnerability in Rails Active Storage Disclosed

Critical RCE Vulnerability in Rails Active Storage Disclosed

First seen 30 Jul 2026, 15:40 UTC EthiackHerodevsReddit 75% similarity 79.5

Article Content

Browse articles
ThreatCluster

On July 29, 2026, the Ruby on Rails security team published CVE-2026-66066, a critical arbitrary file read and remote code execution (RCE) vulnerability in Active Storage. Discovered by the Ethiack research team, this flaw affects default configurations of Rails 6.x, 7.x, and 8.x that utilize the vips image processor. Attackers can exploit this vulnerability to read arbitrary files on the server, including sensitive credentials, without authentication in certain setups. The vulnerability has been assigned a CVSS score of 9.5 and affects an estimated 500,000+ sites. Fixes were released in Rails versions 7.2.3.2, 8.0.5.1, and 8.1.3.1. Users are advised to upgrade immediately to mitigate the risk. The vulnerability is particularly concerning due to the widespread use of Active Storage in production applications.

Key Points: • CVE-2026-66066 is a critical RCE vulnerability affecting Rails Active Storage. • The flaw allows unauthenticated attackers to read arbitrary files on the server. • Patches are available in specific Rails versions; users must upgrade to secure their applications.

ThreatCluster AI How this analysis works

Timeline

2026-07-29
CVE-2026-66066 published
Ruby on Rails disclosed a critical RCE vulnerability in Active Storage affecting versions 6.x to 8.x.
Herodevs
2026-07-29
Vulnerability discovered by Ethiack
The Ethiack research team reported the critical flaw, named KindaRails2Shell, affecting default Rails configurations.
Ethiack
2026-07-30
Patches released for affected Rails versions
Rails released updates in versions 7.2.3.2, 8.0.5.1, and 8.1.3.1 to address the vulnerability.
Herodevs

Community

Browse all →