CVE-2026-78380

8.7

RansomLook · RansomLook

RansomLook fails to enforce privacy status for ransomware groups and markets when distributing victim posts, resulting in unauthorized data exposure.

Executive summary

A missing authorization vulnerability in RansomLook allows for the unauthorized disclosure of sensitive ransomware victim data to external channels.

Vulnerability

The application suffers from missing authorization (CWE-862) when distributing information to notification channels. This allows for the exposure of data that should have been kept private based on the configured privacy status of the source.

Business impact

The CVSS score of 8.7 reflects the high impact on data confidentiality. For organizations relying on RansomLook for threat intelligence, this vulnerability could inadvertently leak sensitive victim information to unauthorized parties, potentially violating privacy regulations and compromising ongoing security investigations.

Remediation

Immediate Action: Update to the latest version of RansomLook and verify that privacy enforcement settings are correctly applied in the configuration.

Proactive Monitoring: Review outbound notification logs to ensure that only authorized data is being transmitted to external endpoints.

Compensating Controls: If an update is not immediately feasible, disable external notification channels that are currently distributing data to untrusted or public endpoints.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

Users of the RansomLook platform must treat this as a high-priority security concern due to the risk of sensitive data exposure. Apply the available updates immediately and audit current notification configurations to ensure that privacy status is enforced as intended.

More RansomLook CVEs