Authorization Weakness in RansomLook's Web-Based Configuration Editor
CVE-2026-78387

9.4CRITICAL

Key Information:

Vendor

Ransomlook

Vendor
CVE Published:
24 August 2026

What is CVE-2026-78387?

RansomLook has a vulnerability that stems from an insufficient authorization mechanism in its web-based configuration editor located at the /admin/config endpoint. While this endpoint requires an authenticated session, it lacks the necessary privilege checks, allowing low-privileged users to submit potentially harmful configuration changes. This may lead to alterations in notification settings, authentication configurations, and even disrupt external services. The exposed configuration file can contain sensitive information like passwords and tokens, making the application susceptible to severe security incidents. To mitigate these risks, the vulnerability has been addressed by completely removing the vulnerable /admin/config interface from the application.

Affected Version(s)

ransomlook 0 <= 2.0.0

References

CVSS V4

Score:
9.4
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Jeroen Pinoy
Fafner [_KeyZee_]
.