ZeroHour

CVE-2026-53459

niche

Fail-Open Authentication Bypass in Bambuddy Print Management System

CVSS 4.0
9.3 critical
EPSS
Published
()
Modified
AI analysis

Bambuddy, a self-hosted archive and management system for Bambu Lab 3D printers, contains a fail-open authentication flaw in versions from 0.1.6 up to (but not including) 0.2.4.4. By flooding a public endpoint to exhaust server resources, an attacker can cause database access to fail, which makes the authentication code fail open and grants unauthenticated access to every protected endpoint. Successful exploitation gives a remote attacker full access to the archive and management functions without any credentials, exposing print history, files, and printer control data. Any deployment running an affected version — especially instances exposed directly to the internet — is impacted; version 0.2.4.4 patches the issue. There is no evidence of in-the-wild exploitation and no public proof-of-concept is known, but the attack requires no privileges or user interaction and is rated critical (CVSS 4.0: 9.3).

What to do: Upgrade Bambuddy to version 0.2.4.4 or later immediately. Until patched, remove any internet exposure by placing the instance behind a VPN or an authenticated reverse proxy, and consider rate-limiting or fail2ban-style protections against request flooding on the public endpoint. Review access logs for anomalous request floods or unauthenticated access to protected endpoints that could indicate an attempted or successful bypass.

Affected
Bambuddy>= 0.1.6, < 0.2.4.4
Estimated exposure
nichelikely hundreds to low thousands of self-hosted instances at most — Bambuddy is a niche, community self-hosted project with no published install counts, so even if a fraction of the millions of Bambu Lab printer owners run it, only a small subset would expose it publicly; no scan data is available, so this…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Bambuddy is a self-hosted print archive and management system for Bambu Lab 3D printers. Starting in version 0.1.6 and prior to version 0.2.4.4, a fail-open in the authentication code allows any attacker to bypass authentication by flooding a public endpoint to exhaust resources causing database access to fail, granting unauthenticated access to all protected endpoints. Version 0.2.4.4 patches the issue.

Weakness
CWE-636, CWE-755
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.