Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 15 Sep 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Maziggy
Maziggy bambuddy |
|
| Vendors & Products |
Maziggy
Maziggy bambuddy |
Tue, 15 Sep 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Bambuddy is a self-hosted print archive and management system for Bambu Lab 3D printers. Starting in version 0.1.6 and prior to version 0.2.4.4, a fail-open in the authentication code allows any attacker to bypass authentication by flooding a public endpoint to exhaust resources causing database access to fail, granting unauthenticated access to all protected endpoints. Version 0.2.4.4 patches the issue. | |
| Title | Bambuddy's authentication fails open on database errors, allowing unauthenticated access to all endpoints | |
| Weaknesses | CWE-636 CWE-755 |
|
| References |
|
|
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-09-15T17:25:27.247Z
Reserved: 2026-06-09T16:31:21.495Z
Link: CVE-2026-53459
No data.
Status : Received
Published: 2026-09-15T18:17:22.120
Modified: 2026-09-15T18:17:22.120
Link: CVE-2026-53459
No data.
OpenCVE Enrichment
Updated: 2026-09-15T20:00:07Z