Authorization Flaw in RansomLook Affects Private Data Access
CVE-2026-78372
What is CVE-2026-78372?
RansomLook contains a vulnerability that fails to consistently enforce proper authorization checks when accessing private groups, markets, and ransom notes. An attacker can exploit this weakness remotely, gaining unauthorized access to sensitive information meant for authorized users only. This issue can lead to the exposure of private group names, ransom note content, and associated metadata through various web views and API endpoints. Previously restricted information related to private entities can be queried by unauthorized users, particularly via the /compare functionality, undermining user privacy. The recent patch addresses this issue by implementing stringent privacy checks and improved filtering mechanisms that ensure private identifiers and associated data are not disclosed to unauthorized parties.
Affected Version(s)
ransomlook 0 <= 2.0.0
