Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 28 Aug 2026 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 28 Aug 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Stable Diffusion WebUI through 1.10.1 contains a credential disclosure vulnerability in the /sdapi/v1/cmd-flags endpoint that returns parsed command-line arguments including gradio_auth and api_auth values in cleartext. Unauthenticated attackers can access this endpoint to retrieve configured usernames and passwords, then use them to authenticate to the interface and access the application. | |
| Title | Stable Diffusion WebUI Credential Disclosure via /sdapi/v1/cmd-flags | |
| First Time appeared |
Automatic1111
Automatic1111 stable-diffusion-webui |
|
| Weaknesses | CWE-522 | |
| CPEs | cpe:2.3:a:automatic1111:stable-diffusion-webui:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Automatic1111
Automatic1111 stable-diffusion-webui |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-28T20:22:40.670Z
Reserved: 2026-08-28T11:12:53.387Z
Link: CVE-2026-82288
Updated: 2026-08-28T20:22:37.338Z
Status : Received
Published: 2026-08-28T20:20:20.393
Modified: 2026-08-28T22:16:56.783
Link: CVE-2026-82288
No data.
OpenCVE Enrichment
Updated: 2026-08-28T22:15:04Z