Sensitive Information Exposure in RansomLook Product by RansomLook
CVE-2026-78386

8.7HIGH

Key Information:

Vendor

Ransomlook

Vendor
CVE Published:
24 August 2026

What is CVE-2026-78386?

RansomLook has a vulnerability where sensitive configurations related to operator-side scraping are exposed through unauthenticated API responses. When queried by unauthorized users, these responses could reveal vital information such as authentication headers, session cookies, or credentials used for monitoring. Such exposure allows potential attackers to replicate these credentials against monitored services, undermining the entire scraping protection mechanism. As a mitigation measure, RansomLook has implemented an allowlist of fields for public location records, ensuring that sensitive internal data is not disclosed to unauthenticated callers.

Affected Version(s)

ransomlook 0 <= 2.0.0

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Jeroen Pinoy
Fafner [_KeyZee_]
.