Junglewise Threat Intelligence

CVE-2026-78372: RansomLook authorization bypass in private entities

CVE-2026-78372 · Severity: info · CVSS 5.3 · Published 2026-08-24

Technologies: RansomLook. Vendors: RansomLook.

Executive brief

RansomLook is an intelligence platform that tracks ransomware groups and their operations, with a feature to mark certain groups, markets, and ransom notes as private to restrict access. An authorization flaw allows unauthenticated users to view private information—including group names, ransom note content, and operational metadata—that should be restricted to authorized users. This could expose sensitive threat intelligence and undermine the platform's access controls.

Technical details

RansomLook fails to consistently enforce authorization checks before serving private entities (groups, markets, and ransom notes) through multiple web views and API endpoints. An unauthenticated remote attacker can access restricted content via the /compare endpoint and other API calls without authentication or user interaction. The vulnerability allows extraction of post counts, mirror information, uptime data, and full ransom note content for private entities even when they are filtered from the normal UI. The fix introduces normalized identifiers for private groups and filters private-entity results before returning data to unauthorized callers.

Affected products

  • RansomLook RansomLook prior to commit dc92d6d5c076bcdbf3476aca42daf0260e8d99d7 (2026-08-23)

Timeline

  • 2026-08-24: disclosed
  • 2026-08-23: patched: Fix deployed via commit dc92d6d5c076bcdbf3476aca42daf0260e8d99d7

References

Related threats