CVE-2026-49463
NL Portal Backend Libraries provide backend components for Dutch government portals that interact with residents, customers, suppliers, and partner organizations. The `nl.nl-portal:documenten-api` package through version 3.0.0 and the `nl.nl-portal:besluiten` package from version 1.5.0 through 3.0.0 lack per-user authorization in GraphQL resolvers, allowing an authenticated user to access other users’ document contents, decisions, audit trails, and decision attachments. Version 3.0.1 contains a patch. As a workaround, block the affected document-content and decision-related GraphQL operations at the API gateway or block their GraphQL types entirely.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.5
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- CWE
- CWE-200, CWE-285
- Published
- 2026-09-11
- Last modified
- 2026-09-11
Affected products
- nl-portal nl.nl-portal:besluiten
- nl-portal nl.nl-portal:documenten-api
Weakness type
Related vulnerabilities
- CVE-2026-50025 — Mousehole: Unauthenticated HTTP/WebSocket boundary exposes and mutates MAM cookie state
- CVE-2026-49462 — nl.nl-portal:app has GraphiQL UI and GraphQL schema introspection enabled by default
- CVE-2026-89298 — Keycloak-services: keycloak-services: confidential client secret disclosed to view-clients role via client registration get
- CVE-2026-89248 — AVideo WebRTC Plugin Information Disclosure via status.json.php
- CVE-2026-88059 — Angular: Information Leak via `HttpTransferCache` Bypass When Using `withRequestsMadeViaParent`
- CVE-2026-88013 — rclone: http backend forwards custom/auth headers to a different host on redirect
- CVE-2026-88893 — OpenPanel Unauthenticated Share Lookup Information Disclosure
- CVE-2026-88876 — AVideo PlayerSkins seo.php Missing Authorization Password-Protected VOD