CVE-2026-82288 HIGH

CVE-2026-82288: Stable Diffusion WebUI Credential Disclosure via /sdapi/v1/cmd-flags

Vendor Automatic1111
Product stable-diffusion-webui
Weakness CWE-522 · Insufficiently protected credentials
Published August 28, 2026
Last update August 28, 2026

CVSS base score

8.7/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

What the vulnerability does

01Description

Stable Diffusion WebUI through 1.10.1 contains a credential disclosure vulnerability in the /sdapi/v1/cmd-flags endpoint that returns parsed command-line arguments including gradio_auth and api_auth values in cleartext. Unauthenticated attackers can access this endpoint to retrieve configured usernames and passwords, then use them to authenticate to the interface and access the application.

Key dates

02Disclosure timeline

August 28, 2026 CVE published
August 28, 2026 Record updated