A vulnerability has been found in VSee Clinic 7.1.26/1.3.0 and classified as critical. The impacted element is an unknown function of the file /api/files of the component Files. This manipulation of the argument remark causes improper control of resource identifiers.

This vulnerability is handled as CVE-2026-13381. The attack can be initiated remotely. There is not any exploit available.