PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-49463 nl-portal CVE debrief

CVE-2026-49463 debrief based on the supplied source corpus. The nl.nl-portal:documenten-api package through version 3.0.0 and the nl.nl-portal:besluiten package from version 1.5.0 through 3.0.0 lack per-user authorization in GraphQL resolvers, allowing an authenticated user to access other users' document contents, decisions, audit trails, and decision attachments. Defenders of Dutch government portals should assess exposure to this vulnerability and apply patches or workarounds accordingly.

Vendor
nl-portal
Product
nl.nl-portal:besluiten
CVSS
MEDIUM 6.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-11
Original CVE updated
2026-09-11
Advisory published
2026-09-11
Advisory updated
2026-09-11

Who should care

Defenders of Dutch government portals that interact with residents, customers, suppliers, and partner organizations should assess exposure to this vulnerability and apply patches or workarounds accordingly. They should also verify affected versions and inventory checks.

Why it matters

CVE-2026-49463 allows authenticated users to access unauthorized data in NL Portal Backend Libraries. Defenders of Dutch government portals should assess exposure, apply patches or workarounds, and verify affected versions.

  • Authenticated users may access unauthorized data
  • Defenders need to verify exposure and apply patches or workarounds
  • Vulnerability requires verification of affected versions and inventory checks

Technical summary

The nl.nl-portal:documenten-api package through version 3.0.0 and the nl.nl-portal:besluiten package from version 1.5.0 through 3.0.0 lack per-user authorization in GraphQL resolvers. This allows an authenticated user to access other users' document contents, decisions, audit trails, and decision attachments. The vulnerability requires verification of affected versions and inventory checks. Defenders should prioritize verifying exposure of NL Portal Backend Libraries in their environment, especially if they interact with residents, customers, suppliers, and partner organizations.

Defensive priority

Defenders should prioritize verifying exposure of NL Portal Backend Libraries in their environment, especially if they interact with residents, customers, suppliers, and partner organizations.

Recommended defensive actions

  • Verify exposure of NL Portal Backend Libraries in the environment
  • Check if the affected packages are used in the environment
  • Apply the patch in version 3.0.1 if vulnerable
  • Block affected GraphQL operations at the API gateway if patching is not feasible
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented

Evidence notes

The CVE record and NVD entry provide details on the vulnerability in NL Portal Backend Libraries. The CVE record was published on 2026-09-11T20:17:13.633Z. The vulnerability allows authenticated users to access unauthorized data. Defenders should verify affected versions and apply patches or workarounds. The source corpus provides limited details, so defenders should exercise caution and verify exposure.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-49463 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-49463

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-49463 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-49463

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.