CVE-2026-49463

MEDIUM CVSS 3.1: 6.5 EPSS 0.32%
Updated Sep 11, 2026
Nl-Portal
Parameter Value
CVSS 6.5 (MEDIUM)
Affected Versions 1.5.0 — 3.0.0
Type CWE-200 (Information Exposure), CWE-285 (Improper Authorization)
Vendor Nl-Portal
Public PoC No

NL Portal Backend Libraries provide backend components for Dutch government portals that interact with residents, customers, suppliers, and partner organizations. The `nl.nl-portal:documenten-api` package through version 3.0.0 and the `nl.nl-portal:besluiten` package from version 1.5.0 through 3.0.0 lack per-user authorization in GraphQL resolvers, allowing an authenticated user to access other users’ document contents, decisions, audit trails, and decision attachments. Version 3.0.1 contains a patch.

As a workaround, block the affected document-content and decision-related GraphQL operations at the API gateway or block their GraphQL types entirely.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
Low
Easy to exploit
Privileges Required
Low
Basic privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
High
Complete data leak
Integrity
None
No data modification
Availability
None
No disruption

CVSS Vector v3.1

Vulnerable Products

nl-portal:nl.nl-portal:besluiten nl-portal:nl.nl-portal:documenten-api

Related Vulnerabilities