Security Assessment of Ruby on Rails Active Storage Vulnerability (CVE-2026-66066) for Carbon Black Cloud
search cancel

Security Assessment of Ruby on Rails Active Storage Vulnerability (CVE-2026-66066) for Carbon Black Cloud

book

Article ID: 454195

calendar_today

Updated On:

Products

Carbon Black Cloud Workload Carbon Black Cloud Endpoint Standard Carbon Black Cloud Enterprise EDR

Issue/Introduction

Customers may inquire whether Carbon Black Cloud products—including Workload Appliance, Endpoint Sensors, and Cloud Backend—are vulnerable to CVE-2026-66066, a vulnerability in the Ruby on Rails Active Storage component (variant processing) that could allow arbitrary file read and potential Remote Code Execution (RCE).

Vulnerability:
CVE-2026-66066

Environment

Carbon Black Cloud Workload Appliance: All Supported Versions
Carbon Black Cloud Sensors (Windows, Linux, macOS): All Supported Versions
Carbon Black Cloud Backend Services

Resolution

Carbon Black Cloud products are Not Applicable / Not Impacted by CVE-2026-66066.

  • Carbon Black Cloud Sensors: Endpoint sensors run as native binaries and do not contain, bundle, or rely on Ruby on Rails or the Active Storage component.
  • Carbon Black Cloud Workload Appliance: The appliance architecture does not incorporate or leverage Ruby on Rails Active Storage or its image processing workflows.
  • Carbon Black Cloud Backend: Cloud backend and microservices do not utilize or expose the Ruby on Rails Active Storage component.

Because the vulnerable Ruby on Rails Active Storage component is not present in the Carbon Black Cloud product architecture, the product is not affected, and no customer action is required.