Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
VOLERION
Volerion Security Research

NOT DEFERRED DATABASE

VULNERABILITIES

CVE-2026-13380 Details

Description

VSee Clinic 7.1.26 and VSee Clinic API 1.3.0 exposes cleartext SFTP credentials in the HTTP responses of three unauthenticated endpoints. The credentials are present in these responses only when SFTP connections have been configured within the application. No authentication is required to retrieve these credentials. An unauthenticated remote attacker who observes any of these HTTP responses on an instance where SFTP is configured can obtain the credentials and use them to access the associated SFTP server.

Metrics

CVSS 3.x Severity and Vector Strings:

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.

URLSource(s)Tag(s)
https://labs.sra.io/posts/vseeclinic Security Risk AdvisorsThird Party Advisory
https://vsee.com/clinic Security Risk AdvisorsProduct

Weakness Enumeration

CWE-IDCWE NameSource
CWE-201Insertion of Sensitive Information Into Sent DataSecurity Risk Advisors
CWE-312Cleartext Storage of Sensitive InformationSecurity Risk Advisors

Affected Products

ProductVersions
vsee clinic
7.1.26

CPE

  • cpe:2.3:a:vsee:clinic:7.1.26:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.
vsee clinic api
1.3.0

CPE

  • cpe:2.3:a:vsee:clinic_api:1.3.0:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.

Change History

3 change records found show changes


QUICK INFO

CVE Dictionary Entry:
CVE-2026-13380
NVD Published Date:
Jul 20, 2026
NVD Last Modified:
Aug 14, 2026
Source:
Security Risk Advisors