


Perceptive Security
SOC/SIEM Consultancy

Bambuddy is a self-hosted print archive and management system for Bambu Lab 3D printers. Prior to version 0.1.7, a hardcoded secret key used for signing JWTs is…
Published:
3 februari 2026 om 23:00:00
Alert date:
4 februari 2026 om 21:03:00
Source:
nvd.nist.gov
Mobile & IoT, Identity & Access
CVE-2026-25505 affects Bambuddy, a self-hosted print archive and management system for Bambu Lab 3D printers. The vulnerability involves a hardcoded secret key used for signing JWTs that is checked into source code, and ManyAPI routes that do not check authentication. This allows unauthorized access to the system. The issue affects versions prior to 0.1.7 and has been patched in version 0.1.7. The vulnerability represents a significant authentication bypass issue that could allow attackers to gain unauthorized access to the print management system.
Technical details
Mitigation steps:
Affected products:
Bambuddy
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-25505
https://github.com/maziggy/bambuddy/blob/a9bb8ed8239602bf08a9914f85a09eeb2bf13d15/backend/app/core/auth.py#L28
https://github.com/maziggy/bambuddy/commit/a82f9278d2d587b7042a0858aab79fd8b6e3add9
https://github.com/maziggy/bambuddy/security/advisories/GHSA-gc24-px2r-5qmf
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
