CVE-2026-53459
Bambuddy is a self-hosted print archive and management system for Bambu Lab 3D printers. Starting in version 0.1.6 and prior to version 0.2.4.4, a fail-open in the authentication code allows any attacker to bypass authentication by flooding a public endpoint to exhaust resources causing database access to fail, granting unauthenticated access to all protected endpoints. Version 0.2.4.4 patches the issue.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9.3
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
- EPSS probability
- 0.42%
- CWE
- CWE-636, CWE-755
- Published
- 2026-09-15
- Last modified
- 2026-09-15
Affected products
- maziggy bambuddy
Weakness type
Related vulnerabilities
- CVE-2026-22034 — Snuffleupagus vulnerable to RCE on instances with upload validation enabled but without the VLD package
- CVE-2021-1578 — Cisco Application Policy Infrastructure Controller Privilege Escalation Vulnerability
- CVE-2025-54870 — VTun-ng's failure to initialize encryption modules may cause reversion to plaintext
- CVE-2023-4030 — A vulnerability was reported in BIOS for ThinkPad P14s Gen 2, P15s Gen 2, T14 Gen 2, and T15 Gen 2 that could cause the
- CVE-2026-53913 — Apache Camel Keycloak: KeycloakSecurityPolicy verifies the bearer access token only inside its role and permission checks, so in the default configuration the token is never verified and any non-null bearer value is accepted
- CVE-2026-73421 — NextAuth.js: Configuration errors can cause existence-based auth checks to fail open (auth object populated with an error)
- CVE-2026-40525 — OpenViking < 0.3.9 Authentication Bypass via VikingBot OpenAPI
- CVE-2026-70452 — rsync 3.1.0 < 3.5.0 Access Control Bypass via DNS Resolution Failure