CVE-2026-13381 PUBLISHED

VSee Clinic and API Insecure Direct Object Reference in File API Allows Unauthorized File Access and Deletion

Assigner: SRA
Reserved: 25.06.2026 Published: 20.07.2026 Updated: 20.07.2026

VSee Clinic 7.1.26 and API 1.3.0 contain an Insecure Direct Object Reference (IDOR) vulnerability in the /v1.3.0/api/files endpoint. An authenticated attacker can manipulate the 'remark' request parameter to enumerate, retrieve, and delete files belonging to other users on the application server.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 8.7

Product Status

Vendor VSee
Product Clinic
Versions Default: unknown
  • affected from 7.1.26 to 7.1.26.1 (excl.)
Vendor VSee
Product Clinic
Versions Default: unknown
  • affected from 1.3.0 to 1.3.0.1 (excl.)

Credits

  • Chris Jones (SRA) finder
  • Drew Young (SRA) finder
  • Maguire Younes (SRA) finder

References

Problem Types

  • CWE-639 Authorization bypass through User-Controlled key CWE

Impacts

  • CAPEC-122 Privilege Abuse
  • CAPEC-137 Parameter Injection