Missing Authentication for Critical Function in Paperclip - #VU141312

 

Missing Authentication for Critical Function in Paperclip - #VU141312

Published: August 8, 2026


Vulnerability identifier: #VU141312
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-306
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose sensitive information and perform unauthorized state-changing operations.

The vulnerability exists due to missing authentication for critical functions in multiple API endpoints when handling requests in authenticated mode. A remote user can send crafted requests to access sensitive data and invoke exposed API functionality without authentication checks.

Exposed endpoints include heartbeat run issue retrieval, CLI authentication challenge creation, skill endpoint access, and deployment configuration disclosure.


Affected software

Paperclip

Remediation

Install security update from vendor's website.

Paperclip - update to 2026.416.0

External References

Related Security Bulletins