CVE-2026-41679 – Paperclip

CVSS 10 CRITICAL Zero Day – Immediate Deployment

“A default deployment can become a direct path to complete server compromise.”

Paperclip versions before 2026.416.0 contain an import authorization bypass that allows an unauthenticated attacker to execute code on a network-accessible instance running in authenticated mode. The automated attack requires no credentials or user interaction and can compromise confidentiality, integrity, and availability. The CVSS score is 10.0, which is Critical severity.

Version 2026.416.0 patches the vulnerable authorization path. Public proof-of-concept exploit code is available.

Key Details

Affected Product
Paperclip Paperclipai
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
CWE Classification
CWE-287
Patch this CVE on all your endpoints in under 5 minutes. First 200 endpoints are free forever, scale as needed.