CVE-2026-25505Disclosure(bambuddy / bambuddy)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch bambuddy bambuddy systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Bambuddy is a self-hosted print archive and management system for Bambu Lab 3D printers. Prior to version 0.1.7, a hardcoded secret key used for signing JWTs is checked into source code and ManyAPI routes do not check authentication. This issue has been patched in version 0.1.7.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-306CWE-321

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • bambuddy

Threat summary

  • Patch or workaround signal is available
  • 6 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 6 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 5 mentions (2026-02-04); latest day: 1
  • 6 total mentions across 2 days

Affected systems

Vendors
Products
bambuddy

Deep dive

Activity timeline6 mentions / 2d
01345Mentions · 2026-02-04: 5Mentions · 2026-02-05: 1Patch / Workaround · 2026-02-04: 2Patch / Workaround · 2026-02-05: 1Technical Details · 2026-02-04: 5Technical Details · 2026-02-05: 102-0402-05
Signal classification2 categories
Disclosure
350.0%
Patch
350.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-02-045
Disclosure3Patch2
2026-02-051
Patch1
Full discourse6 posts
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-25505: CRITICAL] Cybersecurity alert: Bambuddy print archive system fixed hardcoded secret key vulnerability in version 0.1.7. Ensure systems are updated to stay secure from potential breaches.#cve,CVE-2026-25505,#cybersecurity https://cvefind.com/CVE-2026-25505

    Post summary

    The advisory reports a critical hardcoded secret key vulnerability in the Bambuddy print archive system, fixed in version 0.1.7; users are urged to update to secure their systems.

    0000060
    583 followersView on X
  • Säkerhetsbloggen@Sakerhetsblogg
    Patch

    CVE-2026-25505 i Bambuddy avslöjar en allvarlig sårbarhet med hårdkodad hemlig nyckel för JWT-signering, vilket möjliggör obehörig åtkomst. Uppdatera genast till version 0.1.7 för att skydda ditt system. #säkerhet #cybersäkerhet #CVE

    Post summary

    The article highlights CVE-2026-25505 in Bambuddy, noting a hard‑coded JWT secret that enables unauthorized access, and urges users to upgrade to version 0.1.7 immediately.

    0000062
    7 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-25505 Bambuddy is a self-hosted print archive and management system for Bambu Lab 3D printers. Prior to version 0.1.7, a hardcoded secret key used for signing JWTs is check… https://www.cve.org/CVERecord?id=CVE-2026-25505

    Post summary

    CVE-2026-25505 identifies a hardcoded secret key used for signing JWTs in Bambuddy versions before 0.1.7.

    00000205
    56.5K followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-25505: Bambuddy Uses Hardcoded Secret K... Hardcoded JWT key in Bambuddy turns 3D printer management into wide-open target; trivial token forgery grants full syst... https://zerodaysignal.com/vulnerability/CVE-2026-25505 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The post announces CVE-2026-25505 affecting Bambuddy, noting a hardcoded JWT key that allows trivial token forgery and full system access, but it provides no PoC, exploit, patch, or evidence of active exploitation.

    0000067
    132 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-25505 - Critical Bambuddy is a self-hosted print archive and management system for Bambu Lab 3D printers. Prior to version 0.1.7, a hardcoded secret key used for signing JWTs is checked into source code a... https://www.thehackerwire.com/vulnerability/CVE-2026-25505/ https://t.co/Ygt8lFPe1l

    Post summary

    The text announces a critical vulnerability (CVE‑2026‑25505) in Bambuddy, highlighting that a hard‑coded secret key used for JWT signing is exposed in source code, but provides no exploit code or evidence of active exploitation.

    0000072
    113 followersView on X
  • PulsePatch.io@pulsepatchio
    Patch

    Bambuddy (CVE-2026-25505) contains a hardcoded secret key and unauthenticated API endpoints, enabling potential bypass of security controls. Update to 0.1.7. #infosec #vulnerability #APIsecurity https://www.pulsepatch.io/posts/cve-2026-25505-bambuddy-hardcoded-secret-key-unauthenticated-api

    Post summary

    Bambuddy CVE‑2026‑25505 exposes a hardcoded secret key and unauthenticated API endpoints; users should update to version 0.1.7 to remediate the vulnerability.

    0000050
    1 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appbambuddybambuddy---

Explore more