CVE-2026-13380
CRITICALVSee Clinic and API Exposes Cleartext SFTP Credentials in Unauthenticated HTTP Responses
Title source: cnaDescription
VSee Clinic 7.1.26 and VSee Clinic API 1.3.0 exposes cleartext SFTP credentials in the HTTP responses of three unauthenticated endpoints. The credentials are present in these responses only when SFTP connections have been configured within the application. No authentication is required to retrieve these credentials. An unauthenticated remote attacker who observes any of these HTTP responses on an instance where SFTP is configured can obtain the credentials and use them to access the associated SFTP server.
References (2)
Core 2
Core References
Third Party Advisory third-party-advisory
https://labs.sra.io/posts/vseeclinic
Product product
https://vsee.com/clinic
Scores
CVSS v4
9.0
EPSS
0.0026
EPSS Percentile
17.9%
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-201
CWE-312
Status
published
Products (2)
VSee/Clinic
1.3.0 - 1.3.0.1
VSee/Clinic
7.1.26 - 7.1.26.1
Published
Jul 20, 2026
Tracked Since
Jul 21, 2026