Authorization Flaw in RansomLook Affects Private Data Access
CVE-2026-78372

9.2CRITICAL

Key Information:

Vendor

Ransomlook

Vendor
CVE Published:
24 August 2026

What is CVE-2026-78372?

RansomLook contains a vulnerability that fails to consistently enforce proper authorization checks when accessing private groups, markets, and ransom notes. An attacker can exploit this weakness remotely, gaining unauthorized access to sensitive information meant for authorized users only. This issue can lead to the exposure of private group names, ransom note content, and associated metadata through various web views and API endpoints. Previously restricted information related to private entities can be queried by unauthorized users, particularly via the /compare functionality, undermining user privacy. The recent patch addresses this issue by implementing stringent privacy checks and improved filtering mechanisms that ensure private identifiers and associated data are not disclosed to unauthorized parties.

Affected Version(s)

ransomlook 0 <= 2.0.0

References

CVSS V4

Score:
9.2
Severity:
CRITICAL
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Jeroen Pinoy
Fafner [_KeyZee_]
.