CVE-2026-13240: Paragraphs - Less critical - Access bypass - SA-CONTRIB-2026-060
Published Jul 10, 2026
·Updated
Missing Authorization vulnerability in Drupal Paragraphs allows Forceful Browsing. This issue affects Paragraphs versions: from 0.0.0 to 1.21.0.
Affected Software
2 affected components
Drupal Paragraphs>=0.0.0<=1.21.0
Md-systems Paragraphs Drupal<1.21
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Paragraphs (Drupal)to a version that resolves this vulnerability.Fixed in 1.21.0Patch SA-CONTRIB-2026-060
Event History
Jul 10, 2026
CVE Published
via MITRE·09:44 PM
Data Sourced
via MITRE·09:44 PM
DescriptionWeakness
Data Sourced
via NVD·10:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-13240?
The severity of CVE-2026-13240 is classified as medium with a score of 6.5 on the CVSS scale.
2
How do I fix CVE-2026-13240?
To fix CVE-2026-13240, update the Drupal Paragraphs module to version 1.21.1 or later.
3
What is the impact of CVE-2026-13240?
CVE-2026-13240 allows for forceful browsing due to a missing authorization vulnerability.
4
Which versions of Paragraphs are affected by CVE-2026-13240?
CVE-2026-13240 affects all versions of Paragraphs from 0.0.0 to 1.21.0.
5
Is user interaction required to exploit CVE-2026-13240?
No, CVE-2026-13240 does not require user interaction to be exploited.