Executive brief
RansomLook is a web-based ransomware intelligence platform used to track threats and victim information. An unauthenticated attacker can access the /export endpoint to download internal databases containing private records marked for authorized users only, including sensitive victim data, market information, and internal tracking details that should remain confidential.
Technical details
The vulnerability is an authorization bypass in the legacy /export/<database> endpoint that fails to enforce authentication and consistent access control. The endpoint permits direct export of internal databases without requiring API credentials, and while some entity types receive limited filtering, private records (groups, markets, posts) are returned unfiltered, bypassing the application's private-entity restrictions. An unauthenticated network-reachable attacker can invoke the endpoint to retrieve sensitive data that should only be accessible to authorized API consumers. The patch removes the unauthenticated export route, implements centralized authorization logic, and requires explicit per-API-key authorization for private-data access.
Affected products
- RansomLook RansomLook before 2.0 (patch date 2026-08-23)
Timeline
- 2026-08-24: disclosed: CVE-2026-78370 published
- 2026-08-23: patched: Patch committed removing unauthenticated export route