CVE-2026-49464

Source
https://cve.org/CVERecord?id=CVE-2026-49464
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-49464.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-49464
Aliases
Published
2026-09-11T20:34:14Z
Modified
2026-09-12T11:46:15Z
Severity
  • 8.1 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N CVSS Calculator
Summary
NL Portal: IDOR allows any authenticated user to complete and tamper with another user's taak
Details

NL Portal Backend Libraries provide backend components for Dutch government portals that interact with residents, customers, suppliers, and partner organizations. The nl.nl-portal:taak package from version 1.5.0 through 3.0.0 fails to verify ownership when processing the submitTaakV2 GraphQL mutation, allowing an authenticated user who knows or guesses another user’s task ID to read its form data, overwrite its submitted data, and mark the task as completed. Version 3.0.1 contains a patch. As a workaround, block the submitTaakV2 mutation at the API gateway or restrict the /graphql endpoint to trusted networks

Database specific
{
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-639"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/49xxx/CVE-2026-49464.json"
}
References

Affected packages

Git / github.com/nl-portal/nl-portal-backend-libraries

Affected ranges

Type
GIT
Repo
https://github.com/nl-portal/nl-portal-backend-libraries
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "1.5.0"
        },
        {
            "fixed": "3.0.1"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Affected versions

0.*
0.0.1
1.*
1.0.0.RELEASE
1.0.1.RELEASE
1.0.2.RELEASE
1.0.3.RELEASE
1.0.5.RELEASE
1.0.6.RELEASE
1.0.7.RELEASE
1.0.8.RELEASE
1.1.1.RELEASE
1.2.5.RELEASE
Other
SNAPSHOT

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-49464.json"