CVE-2026-25505

Bambuddy is a self-hosted print archive and management system for Bambu Lab 3D printers. Prior to version 0.1.7, a hardcoded secret key used for signing JWTs is checked into source code and ManyAPI routes do not check authentication. This issue has been patched in version 0.1.7.
Configurations

Configuration 1 (hide)

cpe:2.3:a:bambuddy:bambuddy:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-02-04 20:16

Updated : 2026-02-27 20:25


NVD link : CVE-2026-25505

Mitre link : CVE-2026-25505

CVE.ORG link : CVE-2026-25505


JSON object : View

Products Affected

bambuddy

  • bambuddy
CWE
CWE-306

Missing Authentication for Critical Function

CWE-321

Use of Hard-coded Cryptographic Key