DevSecOps

Paperclip AI and CVE-2026-41679: how six requests turn a freshly registered user into server root

Paperclip, the platform that bills itself as a control plane for operating zero-human companies, contained a critical hole that turned user self-registration into a direct path to arbitrary code execution on the server with operating system privileges. The vulnerability, registered as CVE-2026-41679 with a CVSS score of 10.0, was discovered by Oasis Security's research team during an assessment of the platform's authenticated and local deployment modes, and its most alarming particularity is not just its maximum severity: it is that the complete exploitation chain reduces to six HTTP requests that any anonymous user with a browser can execute after a few clicks.

Anatomy of the attack chain

The starting point is Paperclip's self-registration system. By design, Paperclip allowed any visitor to register without email verification. That, by itself, is not necessarily a problem: many modern SaaS products allow self-registration and add verifications afterwards. The problem appears when combined with the platform's CLI authorization flow.

Paperclip's CLI authorization flow is designed to authenticate local devices that need to act on behalf of a user. When a user wants to authorize a new device, Paperclip generates a cryptographic challenge that, under normal conditions, must be approved by an administrator or by the account holder themselves. But the concrete implementation had a critical flaw: a newly registered user could approve their own credential challenge. The consequence is that the attacker, after registering as a normal user, managed to turn that account into a persistent API key at board level —the highest privilege level within Paperclip's internal authorization model— without any other actor needing to intervene in the process.

The second step of the chain exploits another authorization asymmetry inside Paperclip. Direct company creation was correctly restricted to instance administrators. But the equivalent import route —the endpoint designed to migrate companies from other instances or from backups— only checked that the requester had board-level access, a permission the attacker had already obtained in the previous step. This asymmetry between the direct route and the import route is a classic vulnerability class: developers secure the obvious route and forget the alternative that offers the same functionality with different controls.

The third step converts administrative access into code execution. Once inside the company import flow, the attacker introduces a bundle containing an agent configured with the process adapter, a legitimate Paperclip feature that launches a specified command as a child process. Waking that agent executes the attacker's command with the operating system privileges of the Paperclip server. The result is full RCE, with the same privileges as the user under which the platform runs.

Why CVSS 10.0

The maximum CVSS score is justified by the combination of factors this vulnerability presents. The attack vector is network, meaning it can be exploited remotely. Attack complexity is low: it does not require special conditions, particular configuration beyond the default deployment, or interaction from legitimate users other than the attacker themselves. No prior privileges are required to start the chain. User interaction is null once self-registration is completed. The scope is changed, which in CVSS metrics means the vulnerability affects resources beyond the vulnerable component —in this case, all tenants and data managed by the Paperclip instance. And impact is high across all three dimensions: confidentiality, integrity and availability.

The changed scope is particularly important from an operational standpoint. In a multi-tenant platform, a compromised Paperclip instance puts at risk the data and operations of every company hosted on it. If your organization uses Paperclip to orchestrate agents that interact with production systems —customers, billing, infrastructure—, a successful exploitation of CVE-2026-41679 on the instance serving your tenant compromises everything those agents could touch.

What was patched and what remains in play

Paperclip fixed CVE-2026-41679 in version v2026.416.0 through two fundamental changes. First, the company import endpoint now requires instance administrator access for imports targeting a new company, and company access for imports targeting an existing one. This check unifies the authorization logic between the direct route and the import route, eliminating the asymmetry the attack chain exploited. The same check now protects both import preview and execution, preventing an attacker from validating the bundle before the access control is applied.

Second, Paperclip hardened the self-registration and CLI authorization flow so that a newly registered user can no longer treat the new-company import route as an instance-administrator operation. Open registration remains available —a deliberate product decision—, but the consequences of registering are no longer the same.

It is important to note that the DNS rebinding advisory that is part of the same Paperclip disclosure group does not identify a specific patched version, which suggests that mitigation may require additional changes in local deployments that go beyond a simple version upgrade. If you operate Paperclip in local or local_trusted mode, updating to v2026.416.0 is necessary but may not be sufficient to mitigate all documented vectors.

Exploit availability changes everything

Rapid7 published a Metasploit module in June 2026 that automates the six-request CVE-2026-41679 attack chain. This is the part that turns a serious vulnerability into a critical operational one: any actor with access to Metasploit can execute the exploit against any vulnerable Paperclip instance they find exposed to the Internet, without needing to understand the underlying mechanics of the attack.

The CISA-ADP enrichment carried by NVD classifies the vulnerability as automatable, with total technical impact and proof-of-concept exploitation available. These three factors together —automation, total impact and public PoC— are the criteria that modern prioritization models like EPSS and SSVC use to push a vulnerability to the front of the remediation backlog. If your organization still has CVE-2026-41679 unpatched in its backlog, the opportunity cost of each additional day of exposure is higher than ever.

At the time of writing, no authoritative source consulted has reported exploitation in the wild. The absence from CISA's KEV does not rule out exploitation, but it does suggest that mass campaigns have not yet started or that the researchers detecting them have not yet published their findings. This should not be interpreted as a reason to relax: the window between exploit availability and large-scale automated campaigns has shortened dramatically in recent years.

Immediate operational recommendations

If you operate Paperclip, the immediate priority is to confirm that all your instances —development, staging and production— are running v2026.416.0 or above. If you find instances on earlier versions, update them today. The upgrade process should not require additional configuration changes beyond your usual deployment pipeline.

In parallel, review self-registration and company import logs from at least three months before public disclosure. Look for new accounts with immediate import activity, especially if the imported bundle contained agents with the process adapter configured. If you find suspicious patterns, assume the instance was targeted by exploitation attempts and rotate all credentials and tokens issued from that instance.

Beyond the response to this specific CVE, this incident is an opportunity to review the authorization model of any similar platform in your stack. The question to ask is: do alternative routes exist to perform privileged actions that verify permissions different from those of the main route? If the answer is yes and those routes are documented but not secured with the same rigor, you have a CVE waiting for a name.

The rise of AI agent orchestration platforms has created a new attack surface that security teams are still learning to model. CVE-2026-41679 will not be the last finding of this kind, and the speed at which platforms are patched and exploits distributed will continue to accelerate. The organizations that survive this new wave will be those that have built continuous update pipelines and behavioral monitoring that treat every new vulnerability in their AI stack with the same urgency as those in their traditional critical infrastructure.