CVE-2026-78370

9.2

RansomLook · RansomLook

RansomLook contains an authorization flaw in its legacy database export functionality, allowing unauthenticated users to access private entity data.

Executive summary

An authorization bypass in the RansomLook database export endpoint permits unauthenticated access to sensitive private intelligence and internal records.

Vulnerability

The application fails to enforce proper authorization checks on the /export/ endpoint. This allows an unauthenticated, remote attacker to retrieve private data, including victim information and ransomware intelligence, by querying the export route directly.

Business impact

The exposure of private ransomware intelligence and internal tracking data poses a significant risk to organizational security operations and victim privacy. With a CVSS score of 9.2, this vulnerability could lead to the leakage of highly sensitive information, potentially undermining incident response efforts and exposing internal research to malicious actors.

Remediation

Immediate Action: Upgrade to the latest version of RansomLook, which removes the insecure legacy export route and implements centralized authorization controls.

Proactive Monitoring: Review web access logs for unauthorized requests directed at the /export/ path, particularly from external or untrusted IP addresses.

Compensating Controls: Restrict access to the RansomLook web interface via network-level controls, such as VPNs or IP whitelisting, to prevent unauthenticated access.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

This is a critical information disclosure vulnerability. Organizations must apply the vendor patch immediately to enforce authorization requirements and prevent the unauthorized extraction of sensitive private data.

More RansomLook CVEs