SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-13240

MEDIUM · CVSS 6.5 EPSS 0.16%

Source: NVD + CISA KEV + EPSS · Published 2026-07-10 · Last synced 2026-08-09

CyberRota Analysis

AI-Generated

Drupal Paragraphs versions 0.0.0 to 1.21.0 are vulnerable to a missing authorization flaw that permits forceful browsing, potentially allowing unauthorized users to access restricted content. Organizations utilizing these versions should prioritize patching this vulnerability to mitigate the risk of data exposure and unauthorized access. This is particularly critical for sites handling sensitive or user-specific information.

CVE
CVE-2026-13240
Severity
MEDIUM
CVSS
6.5
EPSS
0.16%

Original NVD Description

Missing Authorization vulnerability in Drupal Paragraphs allows Forceful Browsing. This issue affects Paragraphs versions: from 0.0.0 to 1.21.0.

Related CVEs

Other vulnerabilities affecting the same vendor(s)