CVE-2026-53459
nicheFail-Open Authentication Bypass in Bambuddy Print Management System
Bambuddy, a self-hosted archive and management system for Bambu Lab 3D printers, contains a fail-open authentication flaw in versions from 0.1.6 up to (but not including) 0.2.4.4. By flooding a public endpoint to exhaust server resources, an attacker can cause database access to fail, which makes the authentication code fail open and grants unauthenticated access to every protected endpoint. Successful exploitation gives a remote attacker full access to the archive and management functions without any credentials, exposing print history, files, and printer control data. Any deployment running an affected version — especially instances exposed directly to the internet — is impacted; version 0.2.4.4 patches the issue. There is no evidence of in-the-wild exploitation and no public proof-of-concept is known, but the attack requires no privileges or user interaction and is rated critical (CVSS 4.0: 9.3).
What to do: Upgrade Bambuddy to version 0.2.4.4 or later immediately. Until patched, remove any internet exposure by placing the instance behind a VPN or an authenticated reverse proxy, and consider rate-limiting or fail2ban-style protections against request flooding on the public endpoint. Review access logs for anomalous request floods or unauthenticated access to protected endpoints that could indicate an attempted or successful bypass.
| Bambuddy | >= 0.1.6, < 0.2.4.4 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Bambuddy is a self-hosted print archive and management system for Bambu Lab 3D printers. Starting in version 0.1.6 and prior to version 0.2.4.4, a fail-open in the authentication code allows any attacker to bypass authentication by flooding a public endpoint to exhaust resources causing database access to fail, granting unauthenticated access to all protected endpoints. Version 0.2.4.4 patches the issue.
- Weakness
- CWE-636, CWE-755
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.