Junglewise Threat Intelligence

CVE-2026-49463: NL Portal Backend Libraries provide backend components for Dutch government portals that interact with residents, customers, suppliers, and

CVE-2026-49463 · Severity: medium · CVSS 6.5 · Published 2026-09-11

Vendors: Maven, NL Portal.

Executive brief

NL Portal is a backend library used to manage citizen portals and government documents. A security flaw allows any logged-in user to view and download sensitive documents and decision records (such as benefit or permit details) belonging to other users. This could lead to a significant breach of personal data confidentiality across the platform.

Technical details

The vulnerability stems from missing 'CommonGroundAuthentication' parameters in GraphQL resolver method signatures within the 'documenten-api' and 'besluiten' modules. Because the authenticated principal was not bound to the resolver, the framework did not enforce user-scoped authorization checks. An attacker with a valid login can use the 'getBesluiten' query to enumerate decision records across the user base and then use discovered IDs to exfiltrate raw document content via 'getDocumentContent'. The issue is resolved in version 3.0.1 by adding the required authentication parameters to the document resolver and removing the vulnerable 'besluiten' module entirely.

Affected products

  • NL Portal nl-portal-backend-libraries (besluiten) >= 1.5.0, <= 3.0.0
  • NL Portal nl-portal-backend-libraries (documenten-api) <= 3.0.0

Timeline

  • 2026-05: disclosed: Discovered during penetration testing engagement
  • 2026-06-03: advisory: Initial internal advisory publication
  • 2026-07-08: patched: Public disclosure and patch availability confirmed

References

Related threats