Git · Ransomlook · CVE-2026-78387
**Name of the Vulnerable Software and Affected Versions**
RansomLook (affected versions not specified)
**Description**
An authorization weakness exists in the web-based configuration editor. The '/admin/config' endpoint requires an authenticated session but fails to perform explicit privilege or administrator authorization checks. This allows an authenticated low-privileged user to submit crafted configuration values that are written directly to the `config/generic.json` file. Affected functionality includes the modification of notification, LDAP, SMTP, and general application settings. Exploitation could enable an attacker to alter security-sensitive behavior, redirect integrations, modify authentication configurations, disrupt external services, or cause a denial of service. Additionally, the configuration editor handles sensitive data such as passwords, tokens, secrets, and API keys, increasing the risk associated with compromised low-privileged accounts.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.