CVE-2026-49464
NL Portal Backend Libraries provide backend components for Dutch government portals that interact with residents, customers, suppliers, and partner organizations. The `nl.nl-portal:taak` package from version 1.5.0 through 3.0.0 fails to verify ownership when processing the `submitTaakV2` GraphQL mutation, allowing an authenticated user who knows or guesses another user’s task ID to read its form data, overwrite its submitted data, and mark the task as completed. Version 3.0.1 contains a patch. As a workaround, block the `submitTaakV2` mutation at the API gateway or restrict the `/graphql` endpoint to trusted networks
Scoring
- Severity
- HIGH
- CVSS base score
- 8.1
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
- CWE
- CWE-639
- Published
- 2026-09-11
- Last modified
- 2026-09-11
Affected products
- nl-portal nl-portal-backend-libraries
Weakness type
Related vulnerabilities
- CVE-2026-90552 — WWBN AVideo Missing Authorization via Playlists_schedules list.json.php
- CVE-2026-90542 — WWBN AVideo Missing Authorization via remindMe.json.php
- CVE-2026-90534 — Flowise before 3.1.4 Cross-Workspace Credential IDOR via node-load-method
- CVE-2026-54258 — Cross-monitor event media authorization bypass in direct event media endpoints
- CVE-2026-81916 — Incorrect Authorization in the Concrete CMS Express Entries Dashboard below version 9.5.3 Allows Entry Creation in an Unauthorized Object
- CVE-2026-81915 — In Concrete CMS below 9.5.3, Page Type update omits object-level authorization
- CVE-2026-62134 — WordPress Starter Templates plugin <= 4.7.5 - Insecure Direct Object References (IDOR) vulnerability
- CVE-2026-62113 — WordPress Slim SEO plugin <= 4.10.0 - Insecure Direct Object References (IDOR) vulnerability