CVE-2026-49464
NL Portal: IDOR allows any authenticated user to complete and tamper with another user's taak
NL Portal Backend Libraries provide backend components for Dutch government portals that interact with residents, customers, suppliers, and partner organizations. The `nl.nl-portal:taak` package from version 1.5.0 through 3.0.0 fails to verify ownership when processing the `submitTaakV2` GraphQL mutation, allowing an authenticated user who knows or guesses another userβs task ID to read its form data, overwrite its submitted data, and mark the task as completed. Version 3.0.1 contains a patch. As a workaround, block the `submitTaakV2` mutation at the API gateway or restrict the `/graphql` endpoint to trusted networks
| CWE | CWE-639 |
| Vendor | nl-portal |
| Product | nl-portal-backend-libraries |
| Published | Sep 11, 2026 |
| Last Updated | Sep 15, 2026 |
Get instant alerts for nl-portal nl-portal-backend-libraries
Be the first to know when new high vulnerabilities affecting nl-portal nl-portal-backend-libraries are published β delivered to Slack, Telegram or Discord.
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N