Advisory Paperclip auth-bypass rce
Critical Paperclip Flaw Allowed Admin Access, Code Execution
CVE Tools coverage
Oasis Security has disclosed a critical authorization bypass in the Paperclip AI management platform, tracked as CVE-2026-41679 with a perfect CVSS score of 10. The vulnerability enabled remote attackers to register accounts without email verification and self-approve CLI challenges to gain board-level API access. By exploiting a gap in the company import process, attackers could upload crafted YAML files that executed arbitrary commands with the privileges of the Paperclip server process. The vendor has released a fix that applies strict authorization checks to import flows and tightens company scoping, also addressing related issues involving data disclosure and DNS rebinding.