Paragraphs - Moderately critical - Access bypass - SA-CONTRIB-2026-061
Project: ParagraphsDate: 2026-June-24Security risk: Moderately critical 11 ∕ 25 AC:Basic/A:None/CI:None/II:Some/E:Theoretical/TD:UncommonVulnerability: Access bypassAffected versions: <1.21.0CVE IDs: CVE-2026-13241Description: The optional Paragraphs Library module allows the reuse of paragraphs in multiple places.
The module doesn't sufficiently restrict access to direct child paragraphs of library items through API endpoints.
This vulnerability is mitigated by the fact the paragraphs_library module must be in use and general write access to paragraphs through another module must be allowed.Solution: Install the latest version:
- If you use the Paragraphs module for Drupal 8.x, upgrade to Paragraphs 8.x-1.21
Reported By:
Fixed By:
Coordinated By:
- Greg Knaddison (greggles) of the Drupal Security Team
- Juraj Nemec (poker10) of the Drupal Security Team

