Junglewise Threat Intelligence

CVE-2026-78553: RansomLook insecure Flask session key file permissions

CVE-2026-78553 · Severity: info · Published 2026-08-24

Technologies: RansomLook. Vendors: RansomLook.

Executive brief

RansomLook is a web application for tracking ransomware incidents. The application creates a cryptographic secret key used for signing user session cookies with overly permissive file permissions (0644 instead of 0600), allowing any local user on the system to read it. An attacker with local access can use this key to forge valid session cookies, impersonate legitimate users including administrators, and gain complete control over the application's authentication system.

Technical details

This is an insecure file permissions vulnerability affecting the Flask session-signing key file. The secret_key file is created with default process umask (typically resulting in 0644 permissions) rather than restrictive permissions (0600), making it readable by any local user. The exposed key is cryptographic material used to sign Flask session cookies and derive legacy API keys. An attacker with local file-system access can read the key and generate valid session cookies to impersonate any user, including administrators. In LDAP authentication configurations, exploitation is particularly easy because the session loader accepts usernames that do not correspond to local users. A patch has been released that creates new key files atomically with 0600 permissions and restricts permissions on existing files during startup.

Affected products

  • RansomLook RansomLook

Timeline

  • 2026-08-24: disclosed
  • 2026-08-24: patched: Patch released in commit df9d47e

References

Related threats