CVE-2026-78370
9.2RansomLook · RansomLook
RansomLook contains an authorization flaw in its legacy database export functionality, allowing unauthenticated users to access private entity data.
Executive summary
An authorization bypass in the RansomLook database export endpoint permits unauthenticated access to sensitive private intelligence and internal records.
Vulnerability
The application fails to enforce proper authorization checks on the /export/
Business impact
The exposure of private ransomware intelligence and internal tracking data poses a significant risk to organizational security operations and victim privacy. With a CVSS score of 9.2, this vulnerability could lead to the leakage of highly sensitive information, potentially undermining incident response efforts and exposing internal research to malicious actors.
Remediation
Immediate Action: Upgrade to the latest version of RansomLook, which removes the insecure legacy export route and implements centralized authorization controls.
Proactive Monitoring: Review web access logs for unauthorized requests directed at the /export/ path, particularly from external or untrusted IP addresses.
Compensating Controls: Restrict access to the RansomLook web interface via network-level controls, such as VPNs or IP whitelisting, to prevent unauthenticated access.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
This is a critical information disclosure vulnerability. Organizations must apply the vendor patch immediately to enforce authorization requirements and prevent the unauthorized extraction of sensitive private data.