Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-78387— RansomLook Missing Authorization in Web Configuration Editor Allows Application Configuration Modification

Quick assessment

Affected
ransomlook ransomlook
Exploitation
Public or AI PoC available; prioritize validation
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

RansomLook 的 Web 配置编辑器存在授权缺陷,该编辑器通过 端点暴露。虽然该端点要求用户具备已认证的会话,但在允许访问配置管理功能之前,未执行明确的权限或管理员授权检查。 能够访问该端点的低权限已认证用户可以提交精心构造的配置值,这些值会被直接写入应用程序的 文件。受影响的功能允许修改包括通知、LDAP、SMTP 和通用应用程序设置在内的多个配置部分。成功利用此漏洞可能导致攻击者更改对安全敏感的应用程序行为、重定向集成或通知、修改与认证相关的配置、中断外部服务,或使 RansomLook 实例无法使用。

CVSS 9.4 · Critical
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-78387

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
RansomLook Missing Authorization in Web Configuration Editor Allows Application Configuration Modification
Source: CVE Program / CVE List V5
Vulnerability Description
RansomLook contains an authorization weakness in the web-based configuration editor exposed through the /admin/config endpoint. The endpoint requires an authenticated session but does not perform an explicit privilege or administrator authorization check before allowing access to configuration-management functionality. An authenticated low-privileged user able to access the endpoint can submit crafted configuration values that are written directly to the application's config/generic.json file. The affected functionality permits modification of configuration sections including notification, LDAP, SMTP, and general application settings. Successful exploitation could therefore allow an attacker to alter security-sensitive application behavior, redirect integrations or notifications, modify authentication-related configuration, disrupt external services, or render the RansomLook installation unavailable. The configuration editor also operated on a configuration file containing sensitive values such as passwords, tokens, secrets, and API keys. Although the affected version contains logic intended to prevent recognized secret values from being returned to the browser, exposing configuration management through insufficiently authorized web functionality significantly increases the impact of a compromised or low-privileged account. The patch resolves the issue by completely removing the /admin/config route and associated configuration-editing interface, preventing application configuration from being modified through the web UI.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Source: CVE Program / CVE List V5
Vulnerability Type
授权机制缺失
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
ransomlook ransomlook 0 ~ 2.0.0 -

II. Public POCs for CVE-2026-78387

# POC Description Source Link Shenlong Link
AI-Generated POC Premium
Qwen3.6-35B-A3B · 9952 chars
Pro+ exclusive includes:
Vulnerability reproduction recording (real sandbox build + trigger, exclusive)
In-depth vulnerability mechanism
Trigger conditions & impact
Full executable POC code
Exploit chain & mitigation
POC zip download
100+ AI POC generations per month

III. Intelligence Information for CVE-2026-78387

登录查看更多情报信息。

Same Patch Batch · ransomlook · 2026-08-24 · 13 CVEs total

CVE-2026-78555 9.4 CRITICAL RansomLook API Key Disclosure Through /admin/apikeys HTML Source
CVE-2026-78372 9.2 CRITICAL RansomLook Missing Authorization Allows Disclosure of Private Group and Ransom Note Data
CVE-2026-78370 9.2 CRITICAL RansomLook Unauthenticated Database Export Exposes Private Data
CVE-2026-78369 8.8 HIGH Missing Authentication Allows Unauthorized Creation of Crypto Groups in RansomLook
CVE-2026-78391 8.8 HIGH Stored Cross-Site Scripting via Untrusted Cryptocurrency Address Rendering in RansomLook
CVE-2026-78551 8.8 HIGH RansomLook Login Endpoint Allows Timing-Based Username Enumeration and Unthrottled Authent
CVE-2026-78380 8.7 HIGH Private Group and Market Posts Disclosed Through Public Notification Channels in RansomLoo
CVE-2026-78386 8.7 HIGH Unauthenticated Disclosure of Scraping Credentials and Bypass Configuration via RansomLook
CVE-2026-78381 8.2 HIGH RansomLook Arbitrary File Read via Path Traversal in Post screen Field
CVE-2026-78385 8.2 HIGH RansomLook Analysis PDF Generation Allows Server-Side Request Forgery and Arbitrary Local
CVE-2026-78553 7.0 HIGH Insecure Flask Secret-Key File Permissions Allow Local Administrator Session Forgery in Ra
CVE-2026-78378 6.9 MEDIUM Redis Glob Pattern Injection Allows Unauthorized Enumeration of Private Ransomlook Data

IV. Related Vulnerabilities

V. Comments for CVE-2026-78387

No comments yet


Leave a comment