Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-qpm9-h556-mwxm | NL Portal: Missing per-user authorization on document and decision GraphQL queries in nl-portal-backend-libraries |
Fri, 11 Sep 2026 23:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | NL Portal Backend Libraries provide backend components for Dutch government portals that interact with residents, customers, suppliers, and partner organizations. The `nl.nl-portal:documenten-api` package through version 3.0.0 and the `nl.nl-portal:besluiten` package from version 1.5.0 through 3.0.0 lack per-user authorization in GraphQL resolvers, allowing an authenticated user to access other users’ document contents, decisions, audit trails, and decision attachments. Version 3.0.1 contains a patch. As a workaround, block the affected document-content and decision-related GraphQL operations at the API gateway or block their GraphQL types entirely. | |
| Title | NL Portal: Missing per-user authorization on document and decision GraphQL queries in nl-portal-backend-libraries | |
| Weaknesses | CWE-200 CWE-285 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-09-11T19:51:33.853Z
Reserved: 2026-05-30T04:17:43.094Z
Link: CVE-2026-49463
Updated: 2026-09-11T19:51:09.454Z
Status : Received
Published: 2026-09-11T20:17:13.633
Modified: 2026-09-11T20:17:13.633
Link: CVE-2026-49463
No data.
OpenCVE Enrichment
No data.

Github GHSA