Junglewise Threat Intelligence

CVE-2026-49462: NL Portal Backend Libraries GraphQL schema exposure

CVE-2026-49462 · Severity: medium · CVSS 5.3 · Published 2026-09-11

Technologies: NL Portal Backend Libraries. Vendors: NL Portal.

Executive brief

NL Portal Backend Libraries provide the backend infrastructure for Dutch government portals that serve residents, businesses, and partner organizations. Versions up to 3.0.0 exposed the GraphQL developer interface and full API schema without requiring authentication, allowing anyone who could access the endpoint to download a complete map of the API's capabilities and structure. While this alone does not leak user data, it dramatically simplifies attacks against other API vulnerabilities and eliminates the effort required to discover exploitable weaknesses.

Technical details

The vulnerability is an information disclosure flaw affecting GraphQL-based APIs. The root cause is the shipped default configuration enabling the GraphiQL interactive UI (at `/graphiql`) and GraphQL schema introspection without authentication enforcement. An unauthenticated attacker on the network can reach the endpoint, use the UI to issue arbitrary GraphQL queries, and retrieve the full schema via introspection queries (`__schema`, `__type`), which reveals every query, mutation, type, and field the API supports. The vulnerability existed since version 1.5.x under Expedia GraphQL Kotlin (using `graphql.playground.enabled: true`) and continued in 3.0.x after migration to Spring GraphQL (using `spring.graphql.graphiql.enabled: true` with introspection also enabled by default). Version 3.0.1 patches the issue by disabling both settings in the default configuration; workarounds for unpatched versions include configuration overrides or API gateway-level blocking of the UI endpoint and introspection queries.

Affected products

  • NL Portal Backend Libraries up to and including 3.0.0

Timeline

  • 2026-06-03: disclosed: GHSA-9m9w-2vqr-m384 published
  • 2026-05: other: Discovered during penetration testing engagement (phase 1)
  • 2026-09-11: patched: Version 3.0.1 released with CVE-2026-49462

References