Paperclip RCE and auth-bypass flaws multiple vulnerabilities security flaw (CVE-2026-41679)
Vulnerability
Summary
Hide ▲
Show ▼
Paperclip's three vulnerabilities affected authenticated deployments and local development mode, enabling command execution on network servers and a developer's machine through malicious agent imports and DNS rebinding. The most severe issue, CVE-2026-41679 at CVSS 10.0, could be triggered without a pre-existing account or victim interaction in certain network-accessible deployments. The package also included GHSA-xfqj-r5qw-8g4j at CVSS 8.3 for missing API access checks and GHSA-x8hx-rhr2-9rf7 at CVSS 9.6 for a browser-driven localhost attack. Paperclip fixed the main import flaw in v2026.416.0, and Rapid7 released a Metasploit module while CISA/NVD classified the first issue as proof-of-concept exploitation, with no in-the-wild exploitation reported as of August 5, 2026.
Related Happenings
CISA adds CVE-2026-12569 to KEV for PTC Windchill and FlexPLM
Public Sector Action
H score46
First: 26.06.2026 15:31
Last: 26.06.2026 15:31
Sources 1
About this happening:
CISA added CVE-2026-12569 to the KEV catalog after finding active exploitation of PTC Windchill PDMlink and PTC FlexPLM, elevating the flaw to a federal remedi...
CISA adds CVE-2026-12569 to KEV for PTC Windchill and FlexPLM
Public Sector ActionAbout this happening: CISA added CVE-2026-12569 to the KEV catalog after finding active exploitation of PTC Windchill PDMlink and PTC FlexPLM, elevating the flaw to a federal remedi...
CISA KEV patch order for Dell RecoverPoint
Public Sector Action
H score36
First: 19.02.2026 17:30
Last: 19.02.2026 17:30
Sources 1
About this happening:
CISA added CVE-2026-22769 to the KEV catalog and ordered Federal Civilian Executive Branch agencies to secure their networks by February 21. The directive unde...
CISA KEV patch order for Dell RecoverPoint
Public Sector ActionAbout this happening: CISA added CVE-2026-22769 to the KEV catalog and ordered Federal Civilian Executive Branch agencies to secure their networks by February 21. The directive unde...
BRICKSTORM backdoor activity and GRIMBOLT replacement on appliances
Malware Activity
H score29
First: 18.02.2026 12:32
Last: 18.02.2026 12:32
Sources 1
About this happening:
BRICKSTORM is a Golang backdoor used by PRC state-sponsored actors to keep long-term persistence on VMware vSphere, Windows, and appliance environments. ...
BRICKSTORM backdoor activity and GRIMBOLT replacement on appliances
Malware ActivityAbout this happening: BRICKSTORM is a Golang backdoor used by PRC state-sponsored actors to keep long-term persistence on VMware vSphere, Windows, and appliance environments. ...
Timeline
-
04.08.2026 03:00 3 articles · 1d ago
Oasis Security reports three Paperclip vulnerabilities
Initial DisclosureOasis Security published research on Paperclip and described three vulnerabilities affecting authenticated deployments and local development mode. The flaws included CVE-2026-41679 at CVSS 10.0, a path where self-registration without email verification and the CLI authorization flow could turn a new account into a persistent board-level API key, missing access checks on routes that exposed heartbeat data, agent documentation and health information, and a DNS rebinding path that let a malicious webpage import and wake an agent to execute commands on a developer's machine.
Show sources
- Paperclip AI Flaws Let Unauthenticated Attackers Run Commands — www.infosecurity-magazine.com — 05.08.2026 17:30
- Paperclip AI Flaws Let Unauthenticated Attackers Run Commands — www.infosecurity-magazine.com — 05.08.2026 17:30
- Paperclip AI Flaws Let Attackers Run Host Commands via Malicious Agent Imports — thehackernews.com — 05.08.2026 18:14