CVE-2026-13380 CRITICAL

CVE-2026-13380: VSee Clinic and API Exposes Cleartext SFTP Credentials in Unauthenticated HTTP Responses

Vendor Vsee
Product Clinic
Weakness CWE-201
Published July 20, 2026
Last update July 21, 2026

CVSS base score

9.0/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:N

What the vulnerability does

01Description

VSee Clinic 7.1.26 and VSee Clinic API 1.3.0 exposes cleartext SFTP credentials in the HTTP responses of three unauthenticated endpoints. The credentials are present in these responses only when SFTP connections have been configured within the application. No authentication is required to retrieve these credentials. An unauthenticated remote attacker who observes any of these HTTP responses on an instance where SFTP is configured can obtain the credentials and use them to access the associated SFTP server.

Key dates

02Disclosure timeline

July 20, 2026 CVE published
July 21, 2026 Record updated

Related vulnerabilities

04Related CVE