目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%

CVE-2026-78387— RansomLook Web配置编辑器缺少授权允许配置修改

一分钟漏洞结论

影响对象
ransomlook ransomlook
利用判断
存在公开或 AI PoC,应优先验证
建议动作
优先检查厂商安全公告和参考链接中的修复版本;无法立即升级时,限制受影响服务暴露并加强监测。

RansomLook 的 Web 配置编辑器存在授权缺陷,该编辑器通过 端点暴露。虽然该端点要求用户具备已认证的会话,但在允许访问配置管理功能之前,未执行明确的权限或管理员授权检查。 能够访问该端点的低权限已认证用户可以提交精心构造的配置值,这些值会被直接写入应用程序的 文件。受影响的功能允许修改包括通知、LDAP、SMTP 和通用应用程序设置在内的多个配置部分。成功利用此漏洞可能导致攻击者更改对安全敏感的应用程序行为、重定向集成或通知、修改与认证相关的配置、中断外部服务,或使 RansomLook 实例无法使用。

CVSS 9.4 · Critical
获取后续新漏洞提醒 登录后订阅

一、 漏洞 CVE-2026-78387 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
RansomLook Missing Authorization in Web Configuration Editor Allows Application Configuration Modification
来源: CVE Program / CVE List V5
Vulnerability Description
RansomLook contains an authorization weakness in the web-based configuration editor exposed through the /admin/config endpoint. The endpoint requires an authenticated session but does not perform an explicit privilege or administrator authorization check before allowing access to configuration-management functionality. An authenticated low-privileged user able to access the endpoint can submit crafted configuration values that are written directly to the application's config/generic.json file. The affected functionality permits modification of configuration sections including notification, LDAP, SMTP, and general application settings. Successful exploitation could therefore allow an attacker to alter security-sensitive application behavior, redirect integrations or notifications, modify authentication-related configuration, disrupt external services, or render the RansomLook installation unavailable. The configuration editor also operated on a configuration file containing sensitive values such as passwords, tokens, secrets, and API keys. Although the affected version contains logic intended to prevent recognized secret values from being returned to the browser, exposing configuration management through insufficiently authorized web functionality significantly increases the impact of a compromised or low-privileged account. The patch resolves the issue by completely removing the /admin/config route and associated configuration-editing interface, preventing application configuration from being modified through the web UI.
来源: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
来源: CVE Program / CVE List V5
Vulnerability Type
授权机制缺失
来源: CVE Program / CVE List V5

受影响产品

厂商 产品 影响版本 CPE 订阅
ransomlook ransomlook 0 ~ 2.0.0 -

二、漏洞 CVE-2026-78387 的公开POC

# POC 描述 源链接 神龙链接
AI 生成 POC 高级
Qwen3.6-35B-A3B · 6429 chars
Pro+ 专属包含:
漏洞复现靶场录像(真实沙箱构建 + 触发,独家)
漏洞原理深度分析
触发条件与影响面
完整可执行 POC 代码
利用链与缓解建议
POC 打包下载
每月 100+ 条 AI 生成额度

三、漏洞 CVE-2026-78387 的情报信息

登录查看更多情报信息。

同批安全公告 · ransomlook · 2026-08-24 · 共 13 条

CVE-2026-78555 9.4 CRITICAL RansomLook API密钥泄露漏洞
CVE-2026-78372 9.2 CRITICAL RansomLook 缺少授权导致隐私数据泄露
CVE-2026-78370 9.2 CRITICAL RansomLook 未授权数据库导出泄露私
CVE-2026-78369 8.8 HIGH RansomLook 缺少认证导致可未经授权创建加密组
CVE-2026-78391 8.8 HIGH RansomLook 存储型跨站脚本漏洞
CVE-2026-78551 8.8 HIGH RansomLook 登录接口存在用户名枚举及暴力破解漏洞
CVE-2026-78380 8.7 HIGH RansomLook 私域群组和市场帖泄露漏洞
CVE-2026-78386 8.7 HIGH RansomLook API未授权泄露抓取凭证并绕过配置漏洞
CVE-2026-78381 8.2 HIGH Post screen 字段路径遍历导致任意文件读取漏洞
CVE-2026-78385 8.2 HIGH RansomLook PDF生成服务存在SSRF和本地文件读取漏洞
CVE-2026-78553 7.0 HIGH RansomLook Flask密钥权限漏洞允许本地管理员会话伪造
CVE-2026-78378 6.9 MEDIUM Ransomlook 未授权私有数据枚举漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2026-78387

暂无评论


发表评论