CVE Tools
Back to feed
Advisory Paperclip auth-bypass rce

Critical Paperclip Flaw Allowed Admin Access, Code Execution

SecurityWeek·By Ionut Arghire··3 min read
CVE Tools coverage

Oasis Security has disclosed a critical authorization bypass in the Paperclip AI management platform, tracked as CVE-2026-41679 with a perfect CVSS score of 10. The vulnerability enabled remote attackers to register accounts without email verification and self-approve CLI challenges to gain board-level API access. By exploiting a gap in the company import process, attackers could upload crafted YAML files that executed arbitrary commands with the privileges of the Paperclip server process. The vendor has released a fix that applies strict authorization checks to import flows and tightens company scoping, also addressing related issues involving data disclosure and DNS rebinding.