CVE-2026-13381
EUVD-2026-4609320.07.2026, 21:16
VSee Clinic 7.1.26 and API 1.3.0 contain an Insecure Direct Object Reference (IDOR) vulnerability in the /v1.3.0/api/files endpoint. An authenticated attacker can manipulate the 'remark' request parameter to enumerate, retrieve, and delete files belonging to other users on the application server.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| vsee | clinic | 7.1.26 |
| vsee | clinic_api | 1.3.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration