Authentication Bypass in Bambu Lab's Print Archive Management System
CVE-2026-53459
9.3CRITICAL
What is CVE-2026-53459?
Bambuddy, a self-hosted print archive and management system for Bambu Lab 3D printers, is susceptible to an authentication bypass vulnerability due to a fail-open condition in its authentication system. This flaw, present in versions 0.1.6 through 0.2.4.3, allows attackers to flood a public endpoint, causing resource exhaustion that leads to database access failures. As a result, unauthenticated users may gain access to all protected endpoints. Users are advised to update to version 0.2.4.4, which addresses this serious issue.
Affected Version(s)
bambuddy >= 0.1.6, < 0.2.4.4
