Paragraphs - Moderately critical - Access bypass - SA-CONTRIB-2026-061

https://www.drupal.org/sa-contrib-2026-061

Paragraphs - Moderately critical - Access bypass - SA-CONTRIB-2026-061

The optional Paragraphs Library module allows the reuse of paragraphs in multiple places. The module doesn't sufficiently restrict access to direct child paragraphs of library items through API endpoints. This vulnerability is mitigated by the fact the paragraphs_library module must be in use and general write access to paragraphs through another module must be allowed.

Drupal.org