Junglewise Threat Intelligence

CVE-2026-78386: RansomLook API information disclosure via unauthenticated location records

CVE-2026-78386 · Severity: info · Published 2026-08-24

Technologies: RansomLook. Vendors: RansomLook.

Executive brief

RansomLook, a platform that tracks ransomware group activities and dark web markets, exposed sensitive internal configuration data through its public API without requiring authentication. The leak included authentication credentials, CAPTCHA-bypass logic, and scraping environment details used to monitor websites, which could allow attackers to compromise monitored services or defeat the platform's collection mechanisms.

Technical details

The vulnerability is an information disclosure flaw in RansomLook's API endpoint handling for location records. The root cause is insufficient access control and output filtering: the API returned operator-side internal fields (header, init_script, browser) to unauthenticated callers whenever a location record was not explicitly marked private. An unauthenticated remote attacker could directly query the affected API endpoints and extract these sensitive fields verbatim, which may contain authentication headers, session cookies, and anti-bot bypass logic. The patch introduces an explicit allowlist of permitted fields for public location records and strips all operator-side fields before returning data to unauthenticated users. This fix prevents further disclosure of scraping credentials and anti-detection techniques.

Affected products

  • RansomLook RansomLook

Timeline

  • 2026-08-24: disclosed
  • 2026-08-24: patched: Patch applied via commit cc91829 introducing allowlist filtering

References

Related threats