CyberSecurityBoardThreat Intel · CVEs · Products
Critical CVEs

GHSA-xfqj-r5qw-8g4j: Paperclip API Access Control Flaws

August 5, 2026

Multiple API routes in Paperclip lacked proper access checks, exposing sensitive data and control-plane details. Fixed in v2026.416.0 with added authentication and company-access checks.