<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>CVE-2026-13381 on SRA Labs | Cybersecurity Research &amp; Innovation by Security Risk Advisors</title>
    <link>https://labs.sra.io/tags/cve-2026-13381/</link>
    <description>Recent content in CVE-2026-13381 on SRA Labs | Cybersecurity Research &amp; Innovation by Security Risk Advisors</description>
    <generator>Hugo -- gohugo.io</generator>
    <language>en-us</language>
    <lastBuildDate>Mon, 20 Jul 2026 12:00:00 +0000</lastBuildDate><atom:link href="https://labs.sra.io/tags/cve-2026-13381/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Advisory: VSee Clinic</title>
      <link>https://labs.sra.io/posts/vseeclinic/</link>
      <pubDate>Mon, 20 Jul 2026 12:00:00 +0000</pubDate>
      
      <guid>https://labs.sra.io/posts/vseeclinic/</guid>
      <description>&lt;h1 id=&#34;summary&#34;&gt;Summary&lt;/h1&gt;
&lt;p&gt;SRA has identified multiple vulnerabilities in VSee Clinic that can lead to unauthorized access to and deletion of files as well as exposure of SFTP credentials.&lt;/p&gt;
&lt;h1 id=&#34;cve-identifiers&#34;&gt;CVE Identifiers&lt;/h1&gt;
&lt;table&gt;
  &lt;thead&gt;
      &lt;tr&gt;
          &lt;th&gt;CVE ID&lt;/th&gt;
          &lt;th&gt;CVE Name&lt;/th&gt;
      &lt;/tr&gt;
  &lt;/thead&gt;
  &lt;tbody&gt;
      &lt;tr&gt;
          &lt;td&gt;CVE-2026-13380&lt;/td&gt;
          &lt;td&gt;VSee Clinic and API Exposes Cleartext SFTP Credentials in Unauthenticated HTTP Responses&lt;/td&gt;
      &lt;/tr&gt;
      &lt;tr&gt;
          &lt;td&gt;CVE-2026-13381&lt;/td&gt;
          &lt;td&gt;VSee Clinic and API Insecure Direct Object Reference in File API Allows Unauthorized File Access and Deletion&lt;/td&gt;
      &lt;/tr&gt;
  &lt;/tbody&gt;
&lt;/table&gt;
&lt;h1 id=&#34;vulnerability-details--description&#34;&gt;Vulnerability Details / Description&lt;/h1&gt;
&lt;h2 id=&#34;cve-2026-13380-vsee-clinic-and-api-exposes-cleartext-sftp-credentials-in-unauthenticated-http-responses&#34;&gt;CVE-2026-13380: VSee Clinic and API Exposes Cleartext SFTP Credentials in Unauthenticated HTTP Responses&lt;/h2&gt;
&lt;p&gt;VSee Clinic 7.1.26 and VSee Clinic API 1.3.0 exposes cleartext SFTP credentials in the HTTP responses of three unauthenticated endpoints. The credentials are present in these responses only when SFTP connections have been configured within the application. No authentication is required to retrieve these credentials. An unauthenticated remote attacker who observes any of these HTTP responses on an instance where SFTP is configured can obtain the credentials and use them to access the associated SFTP server.&lt;/p&gt;</description>
      <content>&lt;h1 id=&#34;summary&#34;&gt;Summary&lt;/h1&gt;
&lt;p&gt;SRA has identified multiple vulnerabilities in VSee Clinic that can lead to unauthorized access to and deletion of files as well as exposure of SFTP credentials.&lt;/p&gt;
&lt;h1 id=&#34;cve-identifiers&#34;&gt;CVE Identifiers&lt;/h1&gt;
&lt;table&gt;
  &lt;thead&gt;
      &lt;tr&gt;
          &lt;th&gt;CVE ID&lt;/th&gt;
          &lt;th&gt;CVE Name&lt;/th&gt;
      &lt;/tr&gt;
  &lt;/thead&gt;
  &lt;tbody&gt;
      &lt;tr&gt;
          &lt;td&gt;CVE-2026-13380&lt;/td&gt;
          &lt;td&gt;VSee Clinic and API Exposes Cleartext SFTP Credentials in Unauthenticated HTTP Responses&lt;/td&gt;
      &lt;/tr&gt;
      &lt;tr&gt;
          &lt;td&gt;CVE-2026-13381&lt;/td&gt;
          &lt;td&gt;VSee Clinic and API Insecure Direct Object Reference in File API Allows Unauthorized File Access and Deletion&lt;/td&gt;
      &lt;/tr&gt;
  &lt;/tbody&gt;
&lt;/table&gt;
&lt;h1 id=&#34;vulnerability-details--description&#34;&gt;Vulnerability Details / Description&lt;/h1&gt;
&lt;h2 id=&#34;cve-2026-13380-vsee-clinic-and-api-exposes-cleartext-sftp-credentials-in-unauthenticated-http-responses&#34;&gt;CVE-2026-13380: VSee Clinic and API Exposes Cleartext SFTP Credentials in Unauthenticated HTTP Responses&lt;/h2&gt;
&lt;p&gt;VSee Clinic 7.1.26 and VSee Clinic API 1.3.0 exposes cleartext SFTP credentials in the HTTP responses of three unauthenticated endpoints. The credentials are present in these responses only when SFTP connections have been configured within the application. No authentication is required to retrieve these credentials. An unauthenticated remote attacker who observes any of these HTTP responses on an instance where SFTP is configured can obtain the credentials and use them to access the associated SFTP server.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Severity&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;The CVSS base score of this vulnerability has been calculated to be 9.0 (Critical)&lt;/p&gt;
&lt;p&gt;CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:N&lt;/p&gt;
&lt;h2 id=&#34;cve-2026-13381-vsee-clinic-and-api-insecure-direct-object-reference-in-file-api-allows-unauthorized-file-access-and-deletion&#34;&gt;CVE-2026-13381: VSee Clinic and API Insecure Direct Object Reference in File API Allows Unauthorized File Access and Deletion&lt;/h2&gt;
&lt;p&gt;VSee Clinic 7.1.26 and API 1.3.0 contain an Insecure Direct Object Reference (IDOR) vulnerability in the /v1.3.0/api/files endpoint. An authenticated attacker can manipulate the &amp;lsquo;remark&amp;rsquo; request parameter to enumerate, retrieve, and delete files belonging to other users on the application server.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Severity&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;The CVSS base score of this vulnerability has been calculated to be 8.7 (High)&lt;/p&gt;
&lt;p&gt;CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N&lt;/p&gt;
&lt;h1 id=&#34;affected-versions-and-models&#34;&gt;Affected Versions and Models&lt;/h1&gt;
&lt;p&gt;VSee Clinic from 7.1.26 before 7.1.26.1. VSee Clinic API from 1.3.0 before 1.3.0.1.&lt;/p&gt;
&lt;p&gt;VSee Clinic API&amp;rsquo;s default status is uknown for CVE-2026-13380 and unaffected for CVE-2026-13381.&lt;/p&gt;
&lt;h1 id=&#34;mitre-cwe-weakness-enumeration&#34;&gt;MITRE CWE Weakness Enumeration&lt;/h1&gt;
&lt;p&gt;CVE-2026-13380&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;CWE-201 Insertion of sensitive information into sent data&lt;/li&gt;
&lt;li&gt;CWE-312 Cleartext storage of sensitive information&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;CVE-2026-13381&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;CWE-639 Authorization bypass through user-controlled key&lt;/li&gt;
&lt;/ul&gt;
&lt;h1 id=&#34;remediation-options&#34;&gt;Remediation Options&lt;/h1&gt;
&lt;p&gt;Update VSee Clinic to 7.1.26.1 or later and VSee Clinic API to 1.3.0.1 or later&lt;/p&gt;
&lt;h1 id=&#34;source&#34;&gt;Source&lt;/h1&gt;
&lt;p&gt;These vulnerabilities were discovered by Chris Jones, Drew Young, and Maguire Younes as part of research performed by Security Risk Advisors.&lt;/p&gt;
&lt;h1 id=&#34;timeframe&#34;&gt;Timeframe&lt;/h1&gt;
&lt;ul&gt;
&lt;li&gt;June 16, 2026 - SRA submits vulnerability to vendor&lt;/li&gt;
&lt;li&gt;June 24, 2026 - Vendor releases fix&lt;/li&gt;
&lt;li&gt;July 20, 2026 - SRA publishes CVEs and advisory&lt;/li&gt;
&lt;/ul&gt;
</content>
    </item>
    
  </channel>
</rss>
