Security Assessment of Ruby on Rails Active Storage Vulnerability (CVE-2026-66066) for Carbon Black EDR
search cancel

Security Assessment of Ruby on Rails Active Storage Vulnerability (CVE-2026-66066) for Carbon Black EDR

book

Article ID: 454005

calendar_today

Updated On:

Products

Carbon Black EDR Carbon Black EDR (formerly Cb Response)

Issue/Introduction

Customers may inquire whether Carbon Black Endpoint Detection and Response (EDR) is vulnerable to CVE-2026-66066, a vulnerability in the Ruby on Rails Active Storage component (variant processing) that could allow arbitrary file read and potential Remote Code Execution (RCE).

Vulnerability:
CVE-2026-66066

Environment

Carbon Black EDR Server: All Supported Versions
Carbon Black EDR Sensors (Windows, Linux, macOS): All Supported Versions

Resolution

Carbon Black EDR is Not Applicable / Not Impacted by CVE-2026-66066.

  • CB EDR Server: The server architecture does not include or utilize Ruby on Rails or the Active Storage component in any configuration.
  • CB EDR Sensors (Windows / Linux / macOS): Sensors do not include or utilize Ruby or Rails components.

Because the vulnerable Ruby on Rails Active Storage component is not present in the Carbon Black EDR product architecture, the product is not affected, and no customer action is required.