Inadequate Ownership Verification in NL Portal Backend Libraries Affects Dutch Government Systems
CVE-2026-49464

8.1HIGH

Key Information:

Vendor

Nl-portal

Vendor
CVE Published:
11 September 2026

What is CVE-2026-49464?

The NL Portal Backend Libraries, which support various Dutch government portals, contain a vulnerability in the nl.nl-portal:taak package from versions 1.5.0 to 3.0.0. This flaw arises in the submitTaakV2 GraphQL mutation, where ownership verification is insufficient. As a result, an authenticated user can exploit this weakness to access another user's task ID, enabling them to read, overwrite, or mark task data as completed without proper authorization. To mitigate this issue, users should upgrade to version 3.0.1 or employ workarounds, such as blocking the submitTaakV2 mutation at the API gateway or restricting access to the /graphql endpoint to trusted networks.

Affected Version(s)

nl-portal-backend-libraries >= 1.5.0, < 3.0.1

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.