CVE-2026-13240: Md-Systems Paragraphs

Medium severity, CVSS 6.5. EPSS: 0.3% chance of exploitation in the next 30 days.

Missing Authorization vulnerability in Drupal Paragraphs allows Forceful Browsing. This issue affects Paragraphs versions: from 0.0.0 to 1.21.0.

Affected products

  • Md-Systems Paragraphs: before 1.21 (fixed in 1.21)

Published 2026-07-10. Last modified 2026-07-21.