CVE Tools

Critical Paperclip Flaw Allowed Admin Access, Code Execution

SecurityWeekBy Ionut Arghire

AdvisoryPaperclip

Our summary

Oasis Security has disclosed a critical authorization bypass in the Paperclip AI management platform, tracked as CVE-2026-41679 with a perfect CVSS score of 10. The vulnerability enabled remote attackers to register accounts without email verification and self-approve CLI challenges to gain board-level API access. By exploiting a gap in the company import process, attackers could upload crafted YAML files that executed arbitrary commands with the privileges of the Paperclip server process. The vendor has released a fix that applies strict authorization checks to import flows and tightens company scoping, also addressing related issues involving data disclosure and DNS rebinding.

Read at SecurityWeek

SecurityWeek publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store