Bambuddy is a self-hosted print archive and management system for Bambu Lab 3D printers. Starting in version 0.1.6 and prior to version 0.2.4.4, a fail-open in the authentication code allows any attacker to bypass authentication by flooding a public endpoint to exhaust resources causing database access to fail, granting unauthenticated access to all protected endpoints. Version 0.2.4.4 patches the issue.
CVE-2026-53459
This critical-severity CVE scores 9.3 under a secondary CVSS source (NVD's own analysis pending). EPSS exploit probability: 0.4%, top 64% of all CVEs by exploit prediction. GitHub Security Advisory data not yet ingested — confidence will rise once GHSA publishes (typical lag: hours to days for open-source ecosystem CVEs; never for infrastructure-only CVEs).
- High severity, but no confirmed exploitation yet
No vendor fix yet — apply a workaround or compensating control (WAF / firewall / segmentation) and watch for a patch.
- CVSS v3
- 9.3
- EG Score
- 9.3(medium)
- EG Risk
- 57(Track)EG Risk 57/100SSVC: Track
EG Risk is EchelonGraph's 0–100 priority score: it fuses intrinsic severity with real-world exploitation and automatability so you can rank equal-severity CVEs and fix the most dangerous first. Higher = act sooner. Distinct from the 0–10 EG Score (severity).
How it’s computedSeverity93% × 45%Exploitation0% × 40%Automatability100% × 15%Action: Routine — remediate on your standard cadence. - EPSS PROB
- 0%
- EPSS %ILE
- 36%
- KEV
- Not listed
Published
September 15, 2026
Last Modified
September 17, 2026
Advisory Details (5)
Auto-updated Sep 15, 2026v0.2.4.4 - Security Release
Patch available: maziggy/bambuddy v0.2.4.4
https://github.com/maziggy/bambuddy/releases/tag/v0.2.4.4commit 845ad39b19bf (maziggy/bambuddy)
Fix landed in maziggy/bambuddy commit 845ad39b19bf — awaiting tagged release
https://github.com/maziggy/bambuddy/commit/845ad39b19bf99afeea571c6bae09695777e1460bambuddy/CHANGELOG.md at main · maziggy/bambuddy · GitHub
https://github.com/maziggy/bambuddy/blob/main/CHANGELOG.mdbambuddy/backend/app/main.py at 449502cc9fc1cec04f06d31512420eac729fd032 · maziggy/bambuddy · GitHub
https://github.com/maziggy/bambuddy/blob/449502cc9fc1cec04f06d31512420eac729fd032/backend/app/main.py#L5314-L5316bambuddy/backend/app/core/auth.py at 449502cc9fc1cec04f06d31512420eac729fd032 · maziggy/bambuddy · GitHub
https://github.com/maziggy/bambuddy/blob/449502cc9fc1cec04f06d31512420eac729fd032/backend/app/core/auth.py#L473-L483Weakness Classification(2)
MITRE Common Weakness Enumeration — the root-cause categories this CVE belongs to.
Data Freshness Timeline
(refreshed 9× in last 7d / 9× in last 30d)
Each row is a source pipeline that fetched or updated this CVE on that date, with what changed. For example, "NVD update" means NVD published or revised its analysis for this CVE; "MITRE cvelistV5" means we ingested or refreshed it from the CNA feed. Most recent first.
- 2026-09-18 20:03 UTCEG score recompute
- 2026-09-18 19:28 UTCEPSS rescore
- 2026-09-17 21:50 UTCEG score recompute
- 2026-09-17 18:08 UTCEG score recompute
- 2026-09-16 17:55 UTCEG score recompute
- 2026-09-16 14:08 UTCEPSS rescore
- 2026-09-15 18:32 UTCEG score recompute
- 2026-09-15 17:28 UTCEG score recompute
- 2026-09-15 17:28 UTCMITRE cvelistV5first tracked
Frequently asked(5)
What is CVE-2026-53459?
When was CVE-2026-53459 disclosed?
Is CVE-2026-53459 actively exploited?
What is the CVSS score of CVE-2026-53459?
How do I remediate CVE-2026-53459?
Dependency Blast Radius
Explore the affected products and dependency analysis for CVE-2026-53459
Is Your Infrastructure Affected by CVE-2026-53459?
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.