PatchSiren cyber security CVE debrief
CVE-2026-49463 nl-portal CVE debrief
CVE-2026-49463 debrief based on the supplied source corpus. The nl.nl-portal:documenten-api package through version 3.0.0 and the nl.nl-portal:besluiten package from version 1.5.0 through 3.0.0 lack per-user authorization in GraphQL resolvers, allowing an authenticated user to access other users' document contents, decisions, audit trails, and decision attachments. Defenders of Dutch government portals should assess exposure to this vulnerability and apply patches or workarounds accordingly.
- Vendor
- nl-portal
- Product
- nl.nl-portal:besluiten
- CVSS
- MEDIUM 6.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-11
- Original CVE updated
- 2026-09-11
- Advisory published
- 2026-09-11
- Advisory updated
- 2026-09-11
Who should care
Defenders of Dutch government portals that interact with residents, customers, suppliers, and partner organizations should assess exposure to this vulnerability and apply patches or workarounds accordingly. They should also verify affected versions and inventory checks.
Why it matters
CVE-2026-49463 allows authenticated users to access unauthorized data in NL Portal Backend Libraries. Defenders of Dutch government portals should assess exposure, apply patches or workarounds, and verify affected versions.
- Authenticated users may access unauthorized data
- Defenders need to verify exposure and apply patches or workarounds
- Vulnerability requires verification of affected versions and inventory checks
Technical summary
The nl.nl-portal:documenten-api package through version 3.0.0 and the nl.nl-portal:besluiten package from version 1.5.0 through 3.0.0 lack per-user authorization in GraphQL resolvers. This allows an authenticated user to access other users' document contents, decisions, audit trails, and decision attachments. The vulnerability requires verification of affected versions and inventory checks. Defenders should prioritize verifying exposure of NL Portal Backend Libraries in their environment, especially if they interact with residents, customers, suppliers, and partner organizations.
Defensive priority
Defenders should prioritize verifying exposure of NL Portal Backend Libraries in their environment, especially if they interact with residents, customers, suppliers, and partner organizations.
Recommended defensive actions
- Verify exposure of NL Portal Backend Libraries in the environment
- Check if the affected packages are used in the environment
- Apply the patch in version 3.0.1 if vulnerable
- Block affected GraphQL operations at the API gateway if patching is not feasible
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The CVE record and NVD entry provide details on the vulnerability in NL Portal Backend Libraries. The CVE record was published on 2026-09-11T20:17:13.633Z. The vulnerability allows authenticated users to access unauthorized data. Defenders should verify affected versions and apply patches or workarounds. The source corpus provides limited details, so defenders should exercise caution and verify exposure.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-49463 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-49463
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-49463 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-49463
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/nl-portal/nl-portal-backend-libraries/security/advisories/GHSA-qpm9-h556-mwxm
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.