top of page
perceptive_background_267k.jpg

Bambuddy is a self-hosted print archive and management system for Bambu Lab 3D printers. Prior to version 0.1.7, a hardcoded secret key used for signing JWTs is…

Published:

3 februari 2026 om 23:00:00

Alert date:

4 februari 2026 om 21:03:00

Source:

nvd.nist.gov

Click to open the original link from this advisory

Mobile & IoT, Identity & Access

CVE-2026-25505 affects Bambuddy, a self-hosted print archive and management system for Bambu Lab 3D printers. The vulnerability involves a hardcoded secret key used for signing JWTs that is checked into source code, and ManyAPI routes that do not check authentication. This allows unauthorized access to the system. The issue affects versions prior to 0.1.7 and has been patched in version 0.1.7. The vulnerability represents a significant authentication bypass issue that could allow attackers to gain unauthorized access to the print management system.

Technical details

Mitigation steps:

Affected products:

Bambuddy

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page