PatchSiren

nl-portal CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM nl-portal CVE published 2026-09-11

CVE-2026-49463

CVE-2026-49463 debrief based on the supplied source corpus. The nl.nl-portal:documenten-api package through version 3.0.0 and the nl.nl-portal:besluiten package from version 1.5.0 through 3.0.0 lack per-user authorization in GraphQL resolvers, allowing an authenticated user to access other users' document contents, decisions, audit trails, and decision attachments. Defenders of Dutch government portals sh [truncated]

MEDIUM nl-portal CVE published 2026-09-11

CVE-2026-49462

CVE-2026-49462 debrief based on the supplied source corpus. The vulnerability in NL Portal Backend Libraries versions up to 3.0.0 allows attackers to map and exploit APIs, lowering the bar for finding and exploiting other weaknesses. This is achieved through exposed GraphQL developer features without authentication, specifically the GraphiQL playground and schema introspection. Defenders should assess exp [truncated]