CVE-2026-78372

9.2

RansomLook · RansomLook

RansomLook fails to enforce authorization checks, allowing unauthenticated attackers to retrieve private group information, ransom notes, and metadata via web and API endpoints.

Executive summary

A critical authorization vulnerability in RansomLook allows unauthenticated remote attackers to exfiltrate sensitive private data.

Vulnerability

This is a missing authorization flaw (CWE-862) where the software fails to validate user permissions before exposing private entities. The vulnerability is accessible to unauthenticated remote attackers who can query web views and API endpoints to bypass intended access restrictions.

Business impact

The exploitation of this vulnerability leads to the unauthorized disclosure of sensitive, private information, including ransom notes and group metadata. Given the CVSS score of 9.2, this represents a critical risk to data confidentiality, potentially resulting in severe reputational damage and the exposure of proprietary or sensitive intelligence.

Remediation

Immediate Action: Upgrade to the latest version of RansomLook, which includes the necessary privacy checks to filter unauthorized access.

Proactive Monitoring: Review web server and API access logs for unusual patterns or high-frequency requests targeting the /compare functionality or private group identifiers.

Compensating Controls: Implement strict network-level access controls or a Web Application Firewall (WAF) to block unauthorized access to sensitive API endpoints until the patch can be deployed.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

This vulnerability presents a significant risk to data privacy and should be addressed immediately. Administrators must prioritize updating to the latest version to ensure that authorization checks are properly enforced and that private data is no longer exposed to unauthenticated parties.

More RansomLook CVEs