CVE-2026-82288: Stable Diffusion WebUI through 1.10.1 contains a credential disclosure vulnerability in the /sdapi/v1/cmd-flags endpoint
Summary
Stable Diffusion WebUI version 1.10.1 and earlier has a security flaw in the /sdapi/v1/cmd-flags endpoint (a web address that returns system settings) that exposes usernames and passwords in plain text. Attackers without needing to log in can access this endpoint to steal login credentials and then use them to break into the application.
Vulnerability Details
7.5(high)
EPSS: 0.0%
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
network
low
none
none
August 28, 2026
Classification
Taxonomy References
Affected Vendors
Related Issues
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-82288
First tracked: August 28, 2026 at 08:08 PM
Classified by LLM (prompt v3) · confidence: 95%