CVE-2026-25505CRITICAL 9.8EPSS p49.2%

CVE-2026-25505CVE-2026-25505

Description

Bambuddy is a self-hosted print archive and management system for Bambu Lab 3D printers. Prior to version 0.1.7, a hardcoded secret key used for signing JWTs is checked into source code and ManyAPI routes do not check authentication. This issue has been patched in version 0.1.7.

Scoring

CVSS 3.19.8 (CRITICAL)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS0.72% probability of exploitation · percentile 49.2% · 2026-06-18T12:00:27Z
Published2026-02-04
Last modified2026-02-27

Underlying weaknesses· 2

CWE-306CWE-321

References

  1. https://github.com/maziggy/bambuddy/blob/a9bb8ed8239602bf08a9914f85a09eeb2bf13d15/backend/app/core/auth.py#L28
  2. https://github.com/maziggy/bambuddy/blob/main/CHANGELOG.md
  3. https://github.com/maziggy/bambuddy/commit/a82f9278d2d587b7042a0858aab79fd8b6e3add9
  4. https://github.com/maziggy/bambuddy/commit/c31f2968889c855f1ffacb700c2c9970deb2a6fb
  5. https://github.com/maziggy/bambuddy/pull/225
  6. https://github.com/maziggy/bambuddy/releases/tag/v0.1.7
  7. https://github.com/maziggy/bambuddy/security/advisories/GHSA-gc24-px2r-5qmf

2

TypeTargetConfidenceTier
WeaknessMissing Authentication for Critical Functioncwe-3060%live
WeaknessUse of Hard-coded Cryptographic Keycwe-3210%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CVE
CVE-2025-65730
CVE
CVE-2025-35940
CVE
CVE-2025-56749
CVE
CVE-2025-52766
CVE
CVE-2026-25555
CVE
CVE-2025-69971
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.