PT-2026-80865 · Unknown · Ransomlook
CVSS v4.0
9.2
Critical
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
RansomLook (affected versions not specified)
Description
Inconsistent authorization checks when accessing groups, markets, and ransom notes marked as private allow an unauthenticated or unauthorized remote attacker to access restricted information. This issue affects several web views and API endpoints, potentially disclosing private group or market names, ransom-note content, and associated metadata. Specifically, the
/compare endpoint can be queried directly with the name of a private entity to retrieve post counts, mirror totals, and uptime, even if the entity is hidden from the user interface. Additionally, ransom-note views and search results lacked consistent filtering, enabling the retrieval of notes associated with private groups.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ransomlook