SEPTEMBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-13380

HIGH · CVSS 7.5 EPSS 0.24%

Source: NVD + CISA KEV + EPSS · Published 2026-07-20 · Last synced 2026-08-19

CyberRota Analysis

AI-Generated

VSee Clinic versions 7.1.26 and API 1.3.0 expose cleartext SFTP credentials in HTTP responses from three unauthenticated endpoints, potentially allowing remote attackers to access sensitive SFTP servers without authentication. Organizations using these versions, especially those with SFTP configured, should prioritize addressing this vulnerability to prevent unauthorized access to their data. Immediate remediation is essential to mitigate the risk of credential theft and subsequent exploitation.

CVE
CVE-2026-13380
Severity
HIGH
CVSS
7.5
EPSS
0.24%

Original NVD Description

VSee Clinic 7.1.26 and VSee Clinic API 1.3.0 exposes cleartext SFTP credentials in the HTTP responses of three unauthenticated endpoints. The credentials are present in these responses only when SFTP connections have been configured within the application. No authentication is required to retrieve these credentials. An unauthenticated remote attacker who observes any of these HTTP responses on an instance where SFTP is configured can obtain the credentials and use them to access the associated SFTP server.

Related CVEs

Other vulnerabilities affecting the same vendor(s)