Medium severity6.5NVD Advisory· Published Jul 10, 2026· Updated Jul 21, 2026
CVE-2026-13240
CVE-2026-13240
Description
Missing Authorization vulnerability in Drupal Paragraphs allows Forceful Browsing. This issue affects Paragraphs versions: from 0.0.0 to 1.21.0.
Affected products
2- Range: from 0.0.0 to 1.21.0
Patches
Vulnerability mechanics
References
1- www.drupal.org/sa-contrib-2026-060nvdThird Party Advisory
News mentions
0No linked articles in our index yet.