Description
NL Portal Backend Libraries provide backend components for Dutch government portals that interact with residents, customers, suppliers, and partner organizations. In versions up to and including 3.0.0, deployments using the shipped default configuration exposed two GraphQL developer features without requiring authentication: the GraphiQL playground, an interactive UI for issuing GraphQL queries; and schema introspection, which lets a caller download the full description of every query, mutation, type, and argument the API supports. Anyone who could reach the `/graphiql` endpoint could open the playground in a browser, pull the full schema, and use that to map out the API and craft calls against it. By itself this does not leak user data, but it removes the guesswork from attacking the rest of the API and significantly lowers the bar for finding and exploiting other weaknesses. Version 3.0.1 patches the issue. As a workaround, override the two settings in deployed configuration.
Published: 2026-09-11
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthenticated exposure of the GraphiQL UI and GraphQL schema introspection
Action: Patch Immediately
AI Analysis

Impact

The vulnerability allows anyone with network access to the /graphiql endpoint to open an interactive GraphiQL interface and retrieve the complete GraphQL schema without authentication. This provides a full map of available queries, mutations, types, and arguments, greatly simplifying future attacks. This is an information‑exposure weakness (CWE-200) caused by unauthenticated access and requires remediation.

Affected Systems

Applications built with nl-portal:nl.nl-portal:app versions up to and including 3.0.0 are affected. The default configuration in those versions enables both the GraphiQL playground and schema introspection, exposing the endpoint publicly. Version 3.0.1 removes these features from the default build; administrators should verify that their installations have been upgraded or, alternatively, that the corresponding configuration settings have been overridden to block unauthenticated access.

Risk and Exploitability

The EPSS score of < 1% reflects a very low probability of exploitation at this time, and the vulnerability is not listed in CISA’s KEV catalog. The CVSS score of 5.3 indicates a medium level of severity. However, because the /graphiql endpoint is reachable over the network without authentication, an attacker can exploit it remotely if no additional network or application controls are in place. Applying the official fix or configuring the settings to disable the endpoint removes the risk entirely.

Generated by OpenCVE AI on September 15, 2026 at 20:08 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade nl-portal:nl.nl-portal:app to version 3.0.1 or later where GraphiQL UI and schema introspection are disabled by default.
  • If an upgrade cannot be performed immediately, modify the deployment configuration to disable the GraphiQL playground and schema introspection endpoints.
  • If disabling the endpoint is not viable, enforce authentication on the GraphiQL endpoint or implement network/application controls such as firewall rules or a web‑application firewall to restrict access to the /graphiql endpoint until a patch or configuration change is applied.

Generated by OpenCVE AI on September 15, 2026 at 20:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 13 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Nl-portal
Nl-portal nl.nl-portal:app
Vendors & Products Nl-portal
Nl-portal nl.nl-portal:app

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description NL Portal Backend Libraries provide backend components for Dutch government portals that interact with residents, customers, suppliers, and partner organizations. In versions up to and including 3.0.0, deployments using the shipped default configuration exposed two GraphQL developer features without requiring authentication: the GraphiQL playground, an interactive UI for issuing GraphQL queries; and schema introspection, which lets a caller download the full description of every query, mutation, type, and argument the API supports. Anyone who could reach the `/graphiql` endpoint could open the playground in a browser, pull the full schema, and use that to map out the API and craft calls against it. By itself this does not leak user data, but it removes the guesswork from attacking the rest of the API and significantly lowers the bar for finding and exploiting other weaknesses. Version 3.0.1 patches the issue. As a workaround, override the two settings in deployed configuration.
Title nl.nl-portal:app has GraphiQL UI and GraphQL schema introspection enabled by default
Weaknesses CWE-1188
CWE-200
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Nl-portal Nl.nl-portal:app
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-14T16:19:42.885Z

Reserved: 2026-05-30T04:17:43.094Z

Link: CVE-2026-49462

cve-icon Vulnrichment

Updated: 2026-09-14T16:19:39.115Z

cve-icon NVD

Status : Deferred

Published: 2026-09-11T20:17:13.463

Modified: 2026-09-30T19:57:08.043

Link: CVE-2026-49462

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T20:15:14Z

Weaknesses
  • CWE-1188

    Initialization of a Resource with an Insecure Default

  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor