PT-2026-61707 · Vsee · Clinic+1

·

CVE-2026-13380

·

Published

2026-07-20

·

Updated

2026-08-14

CVSS v4.0

9.0

Critical

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:N
Name of the Vulnerable Software and Affected Versions VSee Clinic version 7.1.26 VSee Clinic API version 1.3.0
Description Three unauthenticated endpoints expose cleartext SFTP credentials in their HTTP responses. This occurs only when SFTP connections have been configured within the application. An unauthenticated remote attacker can retrieve these credentials without authentication to gain access to the associated SFTP server.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Cleartext Storage of Sensitive Information

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-13380

Affected Products

Clinic
Clinic Api