CVE-2026-78372
- EPSS 0.48%
- Veröffentlicht 24.08.2026 13:09:23
- Zuletzt bearbeitet 26.08.2026 16:49:18
RansomLook does not consistently enforce authorization checks when accessing groups, markets, and ransom notes marked as private. An unauthenticated or otherwise unauthorized remote attacker can access information associated with private entities ...
CVE-2026-78370
- EPSS 0.49%
- Veröffentlicht 24.08.2026 13:03:23
- Zuletzt bearbeitet 26.08.2026 16:49:18
RansomLook contains an authorization flaw in its legacy database export functionality that can allow unauthenticated remote users to retrieve information intended to remain private. The /export/<database> endpoint permits selected internal databases...
CVE-2026-78369
- EPSS 0.5%
- Veröffentlicht 24.08.2026 12:58:01
- Zuletzt bearbeitet 26.08.2026 16:49:18
RansomLook contains a missing authentication vulnerability in the /admin/crypto/group/new endpoint. While the endpoint provides an administrative function for creating new crypto group entries, it was not protected by the application's authentication...
CVE-2026-40584
- EPSS 0.28%
- Veröffentlicht 21.04.2026 17:16:56
- Zuletzt bearbeitet 27.04.2026 19:47:38
RansomLook is a tool to monitor Ransomware groups and markets and extract their victims. Prior to 1.9.0, the API in the affected application improperly filters private location entries in website/web/api/genericapi.py. Because the code removes elemen...