CVE-2026-66066 | Rails prior 7.2.3.2/8.0.5.1/8.1.3.1 Active Storage unrestricted upload
A vulnerability was found in Rails. It has been classified as critical. The affected element is an unknown function of the component Active Storage. This manipulation causes unrestricted upload.
This vulnerability is tracked as CVE-2026-66066. The attack is possible to be carried out remotely. No exploit exists.
Upgrading the affected component is recommended.VulDB Recent EntriesRead More