CVE-2026-82288
Last modified
CVE-2026-82288 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. Stable Diffusion WebUI through 1.10.1 contains a credential disclosure vulnerability in the /sdapi/v1/cmd-flags endpoint that returns parsed command-line arguments including gradio_auth and api_auth values in cleartext. Unauthenticated attackers can access this endpoint to retrieve configured usernames and passwords, then use them to authenticate to the interface and access the application..
Description
Stable Diffusion WebUI through 1.10.1 contains a credential disclosure vulnerability in the /sdapi/v1/cmd-flags endpoint that returns parsed command-line arguments including gradio_auth and api_auth values in cleartext. Unauthenticated attackers can access this endpoint to retrieve configured usernames and passwords, then use them to authenticate to the interface and access the application.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| AUTOMATIC1111 | stable-diffusion-webui | <= 1.10.1 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-82288?
How severe is CVE-2026-82288?
How do I fix CVE-2026-82288?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-82282Atlantis through 0.47.1 fails to authenticate the /github-ap…8
- CVE-2026-82283VoltAgent through 2.1.20 fails to validate conversation owne…8.1
- CVE-2026-82284Quivr versions through 0.0.322 fail to validate chat ownersh…8.1
- CVE-2026-82285bisheng through 2.6.0-fix2 contains a server-side request fo…8.2
- CVE-2026-82286gpt-crawler through 1.5.1 fails to validate the outputFileNa…8.6
- CVE-2026-82287Rybbit before 2.7.0 contains a CORS misconfiguration vulnera…8.1
- CVE-2026-82289Gitingest through 0.3.1 fails to properly validate hostnames…7.4
- CVE-2026-8229A vulnerability was detected in Wavlink NU516U1 240425. The …8.8
- CVE-2026-82290Chainlit through 2.12.0 fails to validate ownership of feedb…5.3
- CVE-2026-82291HeyForm before 3.0.0-rc.8 reflects the request Origin header…8.1
- CVE-2026-8230A flaw has been found in Wavlink NU516U1 240425. The impacte…8.8
- CVE-2026-82306StarRocks through 4.0.13 contains an information disclosure …6.5
Are you affected by CVE-2026-82288?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
