Customers may inquire whether Carbon Black Endpoint Detection and Response (EDR) is vulnerable to CVE-2026-66066, a vulnerability in the Ruby on Rails Active Storage component (variant processing) that could allow arbitrary file read and potential Remote Code Execution (RCE).
Vulnerability:
CVE-2026-66066
Carbon Black EDR Server: All Supported Versions
Carbon Black EDR Sensors (Windows, Linux, macOS): All Supported Versions
Carbon Black EDR is Not Applicable / Not Impacted by CVE-2026-66066.
Because the vulnerable Ruby on Rails Active Storage component is not present in the Carbon Black EDR product architecture, the product is not affected, and no customer action is required.