Junglewise Threat Intelligence

CVE-2026-13381: VSee Clinic cleartext SFTP credential exposure in unauthenticated API responses

CVE-2026-13381 · Severity: info · CVSS 9 · Published 2026-07-20

Executive brief

VSee Clinic, a telehealth platform used for virtual medical consultations, contains a critical security flaw that exposes sensitive server credentials. An unauthenticated attacker can access cleartext SFTP credentials by viewing specific web responses, potentially allowing them to log into the backend file server. This could lead to the unauthorized access, theft, or modification of sensitive patient data and medical records.

Technical details

VSee Clinic 7.1.26 and API 1.3.0 suffer from an information disclosure vulnerability where cleartext SFTP credentials are included in the HTTP responses of three unauthenticated endpoints. This occurs when SFTP connections are configured within the application. An unauthenticated remote attacker can capture these credentials by observing standard HTTP traffic to the affected endpoints. Once obtained, these credentials can be used to authenticate directly to the SFTP server, bypassing application-level access controls to retrieve or manipulate stored files. The vulnerability is addressed in VSee Clinic version 7.1.26.1 and API version 1.3.0.1.

Affected products

  • VSee Clinic 7.1.26 before 7.1.26.1
  • VSee Clinic API 1.3.0 before 1.3.0.1

Timeline

  • 2026-06-16: disclosed: SRA submits vulnerability to vendor
  • 2026-06-24: patched: Vendor releases fix
  • 2026-07-20: advisory: SRA publishes CVE and advisory

References

Related threats