CVE-2026-49463 debrief based on the supplied source corpus. The nl.nl-portal:documenten-api package through version 3.0.0 and the nl.nl-portal:besluiten package from version 1.5.0 through 3.0.0 lack per-user authorization in GraphQL resolvers, allowing an authenticated user to access other users' document contents, decisions, audit trails, and decision attachments. Defenders of Dutch government portals sh [truncated]
CVE-2026-49462 debrief based on the supplied source corpus. The vulnerability in NL Portal Backend Libraries versions up to 3.0.0 allows attackers to map and exploit APIs, lowering the bar for finding and exploiting other weaknesses. This is achieved through exposed GraphQL developer features without authentication, specifically the GraphiQL playground and schema introspection. Defenders should assess exp [truncated]