Description
Bambuddy is a self-hosted print archive and management system for Bambu Lab 3D printers. Starting in version 0.1.6 and prior to version 0.2.4.4, a fail-open in the authentication code allows any attacker to bypass authentication by flooding a public endpoint to exhaust resources causing database access to fail, granting unauthenticated access to all protected endpoints. Version 0.2.4.4 patches the issue.
Published: 2026-09-15
Score: 9.3 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Unauthenticated access to all protected endpoints
Action: Patch Immediately
AI Analysis

Impact

Bambuddy’s authentication module contains a fail‑open condition that triggers when database access fails. An attacker can exploit this by flood‑pinging a public endpoint, exhausting resources and causing the database operation to fail, which the code interprets as an authentication pass. The result is that any request is treated as if it were authenticated, granting full access to all protected API routes and potentially exposing sensitive print job data. This vulnerability is categorized as CWE‑636 (Fail‑open) and CWE‑755 (Incomplete specification), allowing both confidentiality and integrity compromise.

Affected Systems

The affected vendor is maziggy, and the product is Bambuddy, and management system for Bambu Lab 3D printers. Versions starting at 0.1.6 and ending just before 0.2.4.4 are impacted; the issue is fixed in 0.2.4.4.

Risk and Exploitability

The CVSS score of 9.3 indicates a critical vulnerability. Although an EPSS score of <1% is extremely low, the absence of a KEV listing suggests that widespread exploitation has yet been observed. The likely attack path requires network access to a public endpoint to exhaust system resources. Once database access fails, an attacker can perform privileged actions on the platform.

Generated by OpenCVE AI on September 20, 2026 at 14:54 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • 0.2.4.4 or later, where the authentication bypass has been fixed.
  • Implement rate limiting or a Web Application Firewall on the public API endpoint to prevent the flood of requests that trigger the database failure.
  • Monitor system logs for unusually high request volumes or database connection errors and investigate any anomalies promptly.

Generated by OpenCVE AI on September 20, 2026 at 14:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
First Time appeared Maziggy
Maziggy bambuddy
Vendors & Products Maziggy
Maziggy bambuddy

Tue, 15 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description Bambuddy is a self-hosted print archive and management system for Bambu Lab 3D printers. Starting in version 0.1.6 and prior to version 0.2.4.4, a fail-open in the authentication code allows any attacker to bypass authentication by flooding a public endpoint to exhaust resources causing database access to fail, granting unauthenticated access to all protected endpoints. Version 0.2.4.4 patches the issue.
Title Bambuddy's authentication fails open on database errors, allowing unauthenticated access to all endpoints
Weaknesses CWE-636
CWE-755
References
Metrics cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Maziggy Bambuddy
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-17T16:30:18.884Z

Reserved: 2026-06-09T16:31:21.495Z

Link: CVE-2026-53459

cve-icon Vulnrichment

Updated: 2026-09-17T16:30:14.618Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T18:17:22.120

Modified: 2026-09-29T19:07:47.037

Link: CVE-2026-53459

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T15:00:11Z

Weaknesses
  • CWE-636

    Not Failing Securely ('Failing Open')

  • CWE-755

    Improper Handling of Exceptional Conditions