Description
Missing Authorization vulnerability in Drupal Paragraphs allows Forceful Browsing. This issue affects Paragraphs versions: from 0.0.0 to 1.21.0.
Published: 2026-07-10
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Missing authorization in the Drupal Paragraphs module allows attackers to forcefully browse paragraph items. By manipulating request parameters they can access paragraph data that they should not see, potentially revealing confidential content or configuration. This flaw is a typical Access Control weakness (CWE-862).

Affected Systems

Every installation of the Drupal Paragraphs contributed module from its earliest release up to and including version 1.21.0 is vulnerable. The issue is confined to the Paragraphs component and does not impact core Drupal or other contributed modules unless they call Paragraphs API without proper permission checks.

Risk and Exploitability

The EPSS score is below 1%, indicating a low probability of active exploitation. The CVSS score of 6.5 signals a moderate impact primarily on confidentiality and integrity through unauthorized viewing. The vulnerability is not listed in CISA KEV, so there is no known large-scale exploit activity. While the description does not state whether authentication is required, it is reasonable to infer that a user with some level of access to Paragraphs endpoints may be able to exploit the flaw. Given its moderate severity and low exploit likelihood, applying the available patch is the most effective mitigation.

Generated by OpenCVE AI on July 25, 2026 at 19:30 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Drupal Paragraphs module to version 1.22.0 or later to apply the official fix.
  • Restrict paragraph permissions so that only authorized roles can view and manage paragraph items.
  • Audit content access logs for unauthorized paragraph access attempts and adjust roles accordingly.

Generated by OpenCVE AI on July 25, 2026 at 19:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Mon, 13 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}

cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 13 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 13 Jul 2026 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Drupal
Drupal paragraphs
Vendors & Products Drupal
Drupal paragraphs

Fri, 10 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in Drupal Paragraphs allows Forceful Browsing. This issue affects Paragraphs versions: from 0.0.0 to 1.21.0.
Title Paragraphs - Less critical - Access bypass - SA-CONTRIB-2026-060
Weaknesses CWE-862
References

Subscriptions

Drupal Paragraphs
cve-icon MITRE

Status: PUBLISHED

Assigner: drupal

Published:

Updated: 2026-07-13T18:02:03.735Z

Reserved: 2026-06-24T18:00:13.250Z

Link: CVE-2026-13240

cve-icon Vulnrichment

Updated: 2026-07-13T16:29:37.769Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-25T19:45:03Z

Weaknesses