Junglewise Threat Intelligence

CVE-2026-13241: Drupal Paragraphs access bypass in Paragraphs Library

CVE-2026-13241 · Severity: info · CVSS 4.3 · Published 2026-07-10

Technologies: Packagist:Https://Packages.Drupal.Org/8 Drupal/Paragraphs. Vendors: Packagist:Https://Packages.Drupal.Org/8, Drupal.

Executive brief

A vulnerability exists in the Paragraphs module for Drupal, a popular tool used by site builders to create flexible content layouts. An issue in the optional Paragraphs Library component could allow unauthorized users to bypass access restrictions and interact with specific content elements they should not be able to reach. This could potentially lead to unauthorized modifications of content components, though it requires the site to have specific library features enabled and other modules allowing write access.

Technical details

A missing authorization (CWE-862) vulnerability exists in the optional Paragraphs Library sub-module of the Drupal Paragraphs project. The module fails to sufficiently restrict access to direct child paragraphs of library items when accessed via API endpoints. This allows for 'forceful browsing' where an attacker can interact with internal paragraph entities. The vulnerability is mitigated by the requirement that the paragraphs_library sub-module must be active and that the site must have other modules installed that permit general write access to paragraphs. The issue is resolved in version 1.21.0.

Affected products

  • Drupal Paragraphs 0.0.0 to 1.20.0

Timeline

  • 2026-06-24: advisory: Drupal security advisory SA-CONTRIB-2026-061 published
  • 2026-06-24: patched: Version 1.21.0 released to address the issue
  • 2026-07-10: disclosed: CVE-2026-13241 published to NVD

References

Related threats