Inadequate Ownership Verification in NL Portal Backend Libraries Affects Dutch Government Systems
CVE-2026-49464
8.1HIGH
What is CVE-2026-49464?
The NL Portal Backend Libraries, which support various Dutch government portals, contain a vulnerability in the nl.nl-portal:taak package from versions 1.5.0 to 3.0.0. This flaw arises in the submitTaakV2 GraphQL mutation, where ownership verification is insufficient. As a result, an authenticated user can exploit this weakness to access another user's task ID, enabling them to read, overwrite, or mark task data as completed without proper authorization. To mitigate this issue, users should upgrade to version 3.0.1 or employ workarounds, such as blocking the submitTaakV2 mutation at the API gateway or restricting access to the /graphql endpoint to trusted networks.
Affected Version(s)
nl-portal-backend-libraries >= 1.5.0, < 3.0.1
