CVE-2026-78372
ransomlook
RansomLook does not consistently enforce authorization checks when accessing groups, markets, and ransom notes marked as private. An unauthenticated or otherwise unauthorized remote attacker can access information associated with private entities through several web views and API endpoints. The affected functionality can disclose private group or market names, ransom-note content, and metadata associated with private groups. The /compare functionality can also be queried directly with the name of a private entity, allowing an unauthorized user to retrieve information such as post counts, mi...
- CVSS
- 9.2
- EPSS
- - - percentile
- CISA KEV
- Not listed
- Published
- 2026.08.24