Customers may inquire whether Carbon Black Cloud products—including Workload Appliance, Endpoint Sensors, and Cloud Backend—are vulnerable to CVE-2026-66066, a vulnerability in the Ruby on Rails Active Storage component (variant processing) that could allow arbitrary file read and potential Remote Code Execution (RCE).
Vulnerability:
CVE-2026-66066
Carbon Black Cloud Workload Appliance: All Supported Versions
Carbon Black Cloud Sensors (Windows, Linux, macOS): All Supported Versions
Carbon Black Cloud Backend Services
Carbon Black Cloud products are Not Applicable / Not Impacted by CVE-2026-66066.
Because the vulnerable Ruby on Rails Active Storage component is not present in the Carbon Black Cloud product architecture, the product is not affected, and no customer action is required.