Stable Diffusion WebUI through 1.10.1 contains a credential disclosure vulnerability in the /sdapi/v1/cmd-flags endpoint that returns parsed command-line arguments including gradio_auth and api_auth values in cleartext. Unauthenticated attackers can access this endpoint to retrieve configured usernames and passwords, then use them to authenticate to the interface and access the application.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 28 Aug 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Stable Diffusion WebUI through 1.10.1 contains a credential disclosure vulnerability in the /sdapi/v1/cmd-flags endpoint that returns parsed command-line arguments including gradio_auth and api_auth values in cleartext. Unauthenticated attackers can access this endpoint to retrieve configured usernames and passwords, then use them to authenticate to the interface and access the application. | |
| Title | Stable Diffusion WebUI Credential Disclosure via /sdapi/v1/cmd-flags | |
| First Time appeared |
Automatic1111
Automatic1111 stable-diffusion-webui |
|
| Weaknesses | CWE-522 | |
| CPEs | cpe:2.3:a:automatic1111:stable-diffusion-webui:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Automatic1111
Automatic1111 stable-diffusion-webui |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-28T16:19:05.909Z
Reserved: 2026-08-28T11:12:53.387Z
Link: CVE-2026-82288
No data.
No data.
No data.
OpenCVE Enrichment
No data.
Weaknesses