Skip to content
cve — cve-2026-66066

grep -rl "CVE-2026-66066" ./articles

CVE-2026-66066

CVE-2026-66066 leaks the Rails master key to an unauthenticated attacker who uploads an image. The fix ships in Active Storage — but it works by calling into libvips, so a gem upgrade on an old system library may not deliver it. Exploitation started roughly a month after the patch.

1 article — 2026-09-01

Authoritative record

Root Notes reports on this identifier; it does not maintain it. For the vendor advisory, the affected versions and the scoring, NVD and MITRE hold the primary records.

Our coverage

../cve — every identifier we have covered