Back to overview

CVE-2026-13381

HIGH
8.7
CVSS 4.0
Description
VSee Clinic 7.1.26 and API 1.3.0 contain an Insecure Direct Object Reference (IDOR) vulnerability in the /v1.3.0/api/files endpoint. An authenticated attacker can manipulate the 'remark' request parameter to enumerate, retrieve, and delete files belonging to other users on the application server.

Metadata

CVE ID
CVE-2026-13381
State
PUBLISHED
Assigner
SRA
Reserved
2026-06-25 21:22 UTC
Published
2026-07-20 20:12 UTC
Last updated
2026-07-20 20:12 UTC
Primary CWE
CWE-639
CWE-639 Authorization bypass through User-Controlled key
Vendor / Product
VSee / Clinic
Sources
cve.org  ·  NVD

Severity & Metrics

8.7 HIGH CVSS 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Affected products (2)
VendorProductPlatformVersions
VSee Clinic 7.1.26 < 7.1.26.1
VSee Clinic 1.3.0 < 1.3.0.1
Weakness (CWE)
CWESourceDescription
CWE-639 cna CWE-639 Authorization bypass through User-Controlled key
CVSS scores (1)
ScoreSeverityVersionSourceVector
8.7 HIGH 4.0 cna CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Back to overview