CVE-2026-49463: Nl-Portal Nl.nl-Portal:besluiten

Medium severity, CVSS 6.5. EPSS: 0.3% chance of exploitation in the next 30 days.

NL Portal Backend Libraries provide backend components for Dutch government portals that interact with residents, customers, suppliers, and partner organizations. The `nl.nl-portal:documenten-api` package through version 3.0.0 and the `nl.nl-portal:besluiten` package from version 1.5.0 through 3.0.0 lack per-user authorization in GraphQL resolvers, allowing an authenticated user to access other users’ document contents, decisions, audit trails, and decision attachments. Version 3.0.1 contains a patch. As a workaround, block the affected document-content and decision-related GraphQL operations at the API gateway or block their GraphQL types entirely.

Affected products

  • Nl-Portal Nl.nl-Portal:besluiten: from 1.5.0, before 3.0.1 (fixed in 3.0.1)
  • Nl-Portal Nl.nl-Portal:documenten-API: before 3.0.1 (fixed in 3.0.1)

Published 2026-09-11. Last modified 2026-09-30.