CVE-2026-13241: Paragraphs - Moderately critical - Access bypass - SA-CONTRIB-2026-061
Published Jul 10, 2026
·Updated
Missing Authorization vulnerability in Drupal Paragraphs allows Forceful Browsing. This issue affects Paragraphs versions: from 0.0.0 to 1.21.0.
Affected Software
2 affected components
Drupal Paragraphs>=0.0.0<=1.21.0
Md-systems Paragraphs Drupal<1.21
Event History
Jul 10, 2026
CVE Published
via MITRE·09:44 PM
Data Sourced
via MITRE·09:44 PM
DescriptionWeakness
Data Sourced
via NVD·10:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-13241?
The severity of CVE-2026-13241 is rated as medium with a score of 6.5.
2
What is CVE-2026-13241 about?
CVE-2026-13241 refers to a missing authorization vulnerability in Drupal Paragraphs that allows for forceful browsing.
3
Which versions are affected by CVE-2026-13241?
CVE-2026-13241 affects Drupal Paragraphs versions from 0.0.0 to 1.21.0.
4
How do I fix CVE-2026-13241?
To fix CVE-2026-13241, update your Drupal Paragraphs module to a version higher than 1.21.0.
5
What type of vulnerability is CVE-2026-13241?
CVE-2026-13241 is classified as an access bypass vulnerability.