Home · Wiki · Vulnerabilities & CVEs
type: cve · created: 2026-09-23 · updated: 2026-09-23 · tags: [cve] · confidence: high · severity: critical · affected_sectors: [technology] · au_impact: false

CVE-2026-66066

Summary

A critical Ruby on Rails Active Storage flaw, scored CVSS 9.5, in which crafted image uploads can expose process environment variables and application secrets — including master keys, database credentials and cloud storage tokens.

Details

Active Storage is the framework component that handles uploaded files, and the reported trigger is a crafted image: the variant-processing path can be induced to read arbitrary files, which turns any application that accepts user uploads into a disclosure route for its own secrets. That is a worse outcome than a typical Rails RCE because the exposure is the credentials the application uses to reach everything else — the same class of blast radius as the environment-variable exfiltration seen across the 2026 npm supply-chain campaigns. Rails issued urgent patches; the first-party advisory is the Ruby on Rails security discussion for the CVE, cited below alongside the reporting.

Attribute Detail
CVE CVE-2026-66066
CVSS 9.5
Vendor / product Ruby on Rails (Active Storage)
Reported in the digest 2026-07-30

Related Pages

Sources: raw/digests/Cyber-Digest-2026-07-30.md