Description
NL Portal Backend Libraries provide backend components for Dutch government portals that interact with residents, customers, suppliers, and partner organizations. The `nl.nl-portal:documenten-api` package through version 3.0.0 and the `nl.nl-portal:besluiten` package from version 1.5.0 through 3.0.0 lack per-user authorization in GraphQL resolvers, allowing an authenticated user to access other users’ document contents, decisions, audit trails, and decision attachments. Version 3.0.1 contains a patch. As a workaround, block the affected document-content and decision-related GraphQL operations at the API gateway or block their GraphQL types entirely.
Published: 2026-09-11
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information disclosure due to missing per-user authorization in GraphQL queries
Action: Apply patch
AI Analysis

Impact

NL Portal Backend Libraries provide backend components for Dutch government portals that interact with residents, customers, suppliers, and partner organizations. The nl.nl-portal:documenten-api package through version 3.0.0 and the nl.nl-portal:besluiten package from version 1.5.0 through 3.0.0 lack per-user authorization in GraphQL resolvers, allowing an authenticated user to access other users’ document contents, decisions, audit trails, and decision attachments. Version 3.0.1 contains a patch. As a workaround, block the affected document-content and decision-related GraphQL operations at the API gateway or block their GraphQL types entirely.

Affected Systems

The vulnerability affects the nl.nl-portal:documenten-api package up to and including version 3.0.0 and the nl.nl-portal:besluiten package from version 1.5.0 through 3.0.0. Both packages are used in Dutch government portals that handle residents, customers, suppliers, and partner organizations. Version 3.0.1 of each package contains the necessary patch.

Risk and Exploitability

The CVSS score is 6.5, indicating a moderate severity. The EPSS score is < 1%, indicating a very low exploitation probability, but the flaw can be leveraged by any authenticated user who has valid credentials. It is not listed in the CISA KEV catalog, and the vulnerability does not require remote code execution or elevated privileges. The attackers do not need special prerequisites beyond legitimate authentication credentials.

Generated by OpenCVE AI on September 21, 2026 at 03:52 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade nl.nl-portal:documenten-api to version 3.0.1 or later.
  • Upgrade nl.nl-portal:besluiten to version 3.0.1 or later.
  • If an upgrade cannot be applied immediately, block the affected document-content and decision GraphQL operations at the API gateway schema.

Generated by OpenCVE AI on September 21, 2026 at 03:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-qpm9-h556-mwxm NL Portal: Missing per-user authorization on document and decision GraphQL queries in nl-portal-backend-libraries
History

Sun, 13 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Nl-portal
Nl-portal nl.nl-portal:besluiten
Nl-portal nl.nl-portal:documenten-api
Vendors & Products Nl-portal
Nl-portal nl.nl-portal:besluiten
Nl-portal nl.nl-portal:documenten-api

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description NL Portal Backend Libraries provide backend components for Dutch government portals that interact with residents, customers, suppliers, and partner organizations. The `nl.nl-portal:documenten-api` package through version 3.0.0 and the `nl.nl-portal:besluiten` package from version 1.5.0 through 3.0.0 lack per-user authorization in GraphQL resolvers, allowing an authenticated user to access other users’ document contents, decisions, audit trails, and decision attachments. Version 3.0.1 contains a patch. As a workaround, block the affected document-content and decision-related GraphQL operations at the API gateway or block their GraphQL types entirely.
Title NL Portal: Missing per-user authorization on document and decision GraphQL queries in nl-portal-backend-libraries
Weaknesses CWE-200
CWE-285
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

Nl-portal Nl.nl-portal:besluiten Nl.nl-portal:documenten-api
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-11T19:51:33.853Z

Reserved: 2026-05-30T04:17:43.094Z

Link: CVE-2026-49463

cve-icon Vulnrichment

Updated: 2026-09-11T19:51:09.454Z

cve-icon NVD

Status : Deferred

Published: 2026-09-11T20:17:13.633

Modified: 2026-09-30T19:57:08.043

Link: CVE-2026-49463

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T04:00:13Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor

  • CWE-285

    Improper Authorization