CVE-2026-13381

VSee Clinic 7.1.26 and API 1.3.0 contain an Insecure Direct Object Reference (IDOR) vulnerability in the /v1.3.0/api/files endpoint. An authenticated attacker can manipulate the 'remark' request parameter to enumerate, retrieve, and delete files belonging to other users on the application server.
CVSS

No CVSS.

Configurations

No configuration.

History

20 Jul 2026, 21:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-20 21:16

Updated : 2026-07-21 18:16


NVD link : CVE-2026-13381

Mitre link : CVE-2026-13381

CVE.ORG link : CVE-2026-13381


JSON object : View

Products Affected

No product.

CWE
CWE-639

Authorization Bypass Through User-Controlled Key