PT-2026-61707 · Vsee · Clinic+1
CVSS v4.0
9.0
Critical
| Vector | AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:N |
Name of the Vulnerable Software and Affected Versions
VSee Clinic version 7.1.26
VSee Clinic API version 1.3.0
Description
Three unauthenticated endpoints expose cleartext SFTP credentials in their HTTP responses. This occurs only when SFTP connections have been configured within the application. An unauthenticated remote attacker can retrieve these credentials without authentication to gain access to the associated SFTP server.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Cleartext Storage of Sensitive Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Clinic
Clinic Api