High severity7.5NVD Advisory· Published Jul 20, 2026· Updated Aug 14, 2026
CVE-2026-13380
CVE-2026-13380
Description
VSee Clinic 7.1.26 and VSee Clinic API 1.3.0 exposes cleartext SFTP credentials in the HTTP responses of three unauthenticated endpoints. The credentials are present in these responses only when SFTP connections have been configured within the application. No authentication is required to retrieve these credentials. An unauthenticated remote attacker who observes any of these HTTP responses on an instance where SFTP is configured can obtain the credentials and use them to access the associated SFTP server.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- cpe:2.3:a:vsee:clinic_api:1.3.0:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
2- labs.sra.io/posts/vseeclinicnvdThird Party Advisory
- vsee.com/clinicnvdProduct
News mentions
1- ⚡ Weekly Recap: Chrome 0-Day, Router Hijacks, Coder Supply Chain Attack and MoreThe Hacker News · Sep 7, 2026