Junglewise Threat Intelligence

CVE-2026-78370: RansomLook authorization bypass in database export endpoint

CVE-2026-78370 · Severity: info · CVSS 5.3 · Published 2026-08-24

Technologies: RansomLook. Vendors: RansomLook.

Executive brief

RansomLook is a web-based ransomware intelligence platform used to track threats and victim information. An unauthenticated attacker can access the /export endpoint to download internal databases containing private records marked for authorized users only, including sensitive victim data, market information, and internal tracking details that should remain confidential.

Technical details

The vulnerability is an authorization bypass in the legacy /export/<database> endpoint that fails to enforce authentication and consistent access control. The endpoint permits direct export of internal databases without requiring API credentials, and while some entity types receive limited filtering, private records (groups, markets, posts) are returned unfiltered, bypassing the application's private-entity restrictions. An unauthenticated network-reachable attacker can invoke the endpoint to retrieve sensitive data that should only be accessible to authorized API consumers. The patch removes the unauthenticated export route, implements centralized authorization logic, and requires explicit per-API-key authorization for private-data access.

Affected products

  • RansomLook RansomLook before 2.0 (patch date 2026-08-23)

Timeline

  • 2026-08-24: disclosed: CVE-2026-78370 published
  • 2026-08-23: patched: Patch committed removing unauthenticated export route

References

Related threats