Description
Missing Authorization vulnerability in Drupal Paragraphs allows Forceful Browsing. This issue affects Paragraphs versions: from 0.0.0 to 1.21.0.
Published: 2026-07-10
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a missing authorization check in the Drupal Paragraphs module, which allows attackers to forcefully browse paragraph content. This flaw is classified as CWE-862, representing an access control weakness that can expose sensitive data and potentially enable unauthorized editing of paragraph entities. The impact is the compromise of confidentiality and integrity of paragraph information, allowing unauthorized users to read or modify content without legitimate authentication.

Affected Systems

Drupal Paragraphs, version range 0.0.0 through 1.21.0, are affected. All installations within this range may allow unauthenticated access to paragraph data and endpoints.

Risk and Exploitability

The EPSS score is <1% and the vulnerability is not listed in CISA KEV, indicating that the probability of exploitation is currently very low. The flaw can be exploited remotely by sending HTTP requests to paragraph endpoints that lack proper access controls. No authentication is required, so the attack vector is likely wide open to any network user. The CVSS score is 6.5, signifying medium severity, and the overall risk remains moderate, but the absence of a patch makes it a high priority for remediation.

Generated by OpenCVE AI on July 29, 2026 at 09:46 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Paragraphs module to the latest published version, which removes the missing authorization check.
  • If an update cannot be performed immediately, tighten permissions on paragraph routes so that only authorized roles can read or edit paragraph entities.
  • Implement a temporary hardening measure by disabling or restricting the Paragraphs routes on public-facing sites, ensuring unauthenticated users cannot access them until the patch is applied.

Generated by OpenCVE AI on July 29, 2026 at 09:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Mon, 13 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}

cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 13 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 13 Jul 2026 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Drupal
Drupal paragraphs
Vendors & Products Drupal
Drupal paragraphs

Fri, 10 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in Drupal Paragraphs allows Forceful Browsing. This issue affects Paragraphs versions: from 0.0.0 to 1.21.0.
Title Paragraphs - Moderately critical - Access bypass - SA-CONTRIB-2026-061
Weaknesses CWE-862
References

Subscriptions

Drupal Paragraphs
cve-icon MITRE

Status: PUBLISHED

Assigner: drupal

Published:

Updated: 2026-07-13T18:02:48.642Z

Reserved: 2026-06-24T18:00:14.145Z

Link: CVE-2026-13241

cve-icon Vulnrichment

Updated: 2026-07-13T16:30:37.099Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-29T10:00:15Z

Weaknesses