CyberSecurityBoardThreat Intel · CVEs · Products
Critical CVEs

CVE-2026-41679: Paperclip Critical Flaw Allows Remote Code Execution

August 5, 2026

A critical vulnerability in Paperclip's authenticated mode with default registration allows unauthenticated attackers to self-approve credentials and import a malicious agent, leading to arbitrary command execution on the server with CVSS 10.0. Fixed in v2026.416.0.