SEPTEMBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-13381

HIGH · CVSS 8.1 EPSS 0.21%

Source: NVD + CISA KEV + EPSS · Published 2026-07-20 · Last synced 2026-08-19

CyberRota Analysis

AI-Generated

VSee Clinic 7.1.26 and API 1.3.0 are vulnerable to an Insecure Direct Object Reference (IDOR) flaw in the /v1.3.0/api/files endpoint, allowing authenticated attackers to exploit the 'remark' request parameter. This vulnerability enables them to enumerate, access, and delete files belonging to other users, posing a significant risk to user data integrity and confidentiality. Organizations using these versions should prioritize remediation to protect sensitive information from unauthorized access and manipulation.

CVE
CVE-2026-13381
Severity
HIGH
CVSS
8.1
EPSS
0.21%

Original NVD Description

VSee Clinic 7.1.26 and API 1.3.0 contain an Insecure Direct Object Reference (IDOR) vulnerability in the /v1.3.0/api/files endpoint. An authenticated attacker can manipulate the 'remark' request parameter to enumerate, retrieve, and delete files belonging to other users on the application server.

Related CVEs

Other vulnerabilities affecting the same vendor(s)