started · updated
Cybersecurity researchers disclose critical RCE vulnerabilities in Paperclip and SharePoint
Security researchers have disclosed two significant remote code execution (RCE) vulnerabilities affecting different software platforms.
Oasis Security disclosed CVE-2026-41679, a CVSS 10.0 vulnerability in the Paperclip open-source agent orchestration platform. The flaw allows unauthenticated attackers to gain full server control through six API calls. The vulnerability stems from an architectural issue where the system treats agent configuration bundles as executable instructions rather than data. An attacker can register an account without email verification and import a malicious YAML file to execute arbitrary commands as the server's OS user.
Separately, Rapid7 researchers used AI-assisted methods to identify an unauthenticated RCE chain in Microsoft SharePoint. The exploit combines a JWT authentication-bypass vulnerability (CVE-2026-55040) with a flaw in Business Connectivity Services (CVE-2026-63520). This chain allows attackers to assume administrative identities and execute code under the SharePoint site’s Windows service account. The vulnerability affects SharePoint Server Subscription Edition, 2019, and 2016, as well as certain Office Web Apps Server versions, though SharePoint Online is not affected.
Entities
Microsoft · Oasis Security · Paperclip · Rapid7 · SharePoint