ZeroHour

CVE-2026-25505

PoC
CVSS 3.1
9.8 critical
EPSS
<1%p53
Published
()
Modified
Description

Bambuddy is a self-hosted print archive and management system for Bambu Lab 3D printers. Prior to version 0.1.7, a hardcoded secret key used for signing JWTs is checked into source code and ManyAPI routes do not check authentication. This issue has been patched in version 0.1.7.

Vendors
bambuddy
Products
bambuddy
Weakness
CWE-306, CWE-321
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.