CVE-2026-78380
8.7RansomLook · RansomLook
RansomLook fails to enforce privacy status for ransomware groups and markets when distributing victim posts, resulting in unauthorized data exposure.
Executive summary
A missing authorization vulnerability in RansomLook allows for the unauthorized disclosure of sensitive ransomware victim data to external channels.
Vulnerability
The application suffers from missing authorization (CWE-862) when distributing information to notification channels. This allows for the exposure of data that should have been kept private based on the configured privacy status of the source.
Business impact
The CVSS score of 8.7 reflects the high impact on data confidentiality. For organizations relying on RansomLook for threat intelligence, this vulnerability could inadvertently leak sensitive victim information to unauthorized parties, potentially violating privacy regulations and compromising ongoing security investigations.
Remediation
Immediate Action: Update to the latest version of RansomLook and verify that privacy enforcement settings are correctly applied in the configuration.
Proactive Monitoring: Review outbound notification logs to ensure that only authorized data is being transmitted to external endpoints.
Compensating Controls: If an update is not immediately feasible, disable external notification channels that are currently distributing data to untrusted or public endpoints.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
Users of the RansomLook platform must treat this as a high-priority security concern due to the risk of sensitive data exposure. Apply the available updates immediately and audit current notification configurations to ensure that privacy status is enforced as intended.