Authorization Weakness in RansomLook's Web-Based Configuration Editor
CVE-2026-78387
What is CVE-2026-78387?
RansomLook has a vulnerability that stems from an insufficient authorization mechanism in its web-based configuration editor located at the /admin/config endpoint. While this endpoint requires an authenticated session, it lacks the necessary privilege checks, allowing low-privileged users to submit potentially harmful configuration changes. This may lead to alterations in notification settings, authentication configurations, and even disrupt external services. The exposed configuration file can contain sensitive information like passwords and tokens, making the application susceptible to severe security incidents. To mitigate these risks, the vulnerability has been addressed by completely removing the vulnerable /admin/config interface from the application.
Affected Version(s)
ransomlook 0 <= 2.0.0
