Improper Authorization Affecting nl.nl-portal:besluiten package, versions [1.5.0,3.0.1)


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Improper Authorization vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-JAVA-NLNLPORTAL-17912781
  • published9 Jul 2026
  • disclosed8 Jul 2026
  • creditUnknown

Introduced: 8 Jul 2026

CVE-2026-49463  (opens in a new tab)
CWE-285  (opens in a new tab)

How to fix?

Upgrade nl.nl-portal:besluiten to version 3.0.1 or higher.

Overview

Affected versions of this package are vulnerable to Improper Authorization in the GraphQL API's getDocumentContent and besluiten operations. An attacker can access sensitive personal data belonging to other users by querying these endpoints without proper authorization checks. This is achieved by enumerating decision records and retrieving associated document contents through the exposed GraphQL queries.

Workaround

This vulnerability can be mitigated by blocking the following GraphQL operations at the API gateway: getDocumentContent, getBesluiten, getBesluit, getBesluitAuditTrails, getBesluitAuditTrail, getBesluitDocumenten, getBesluitDocument. If per-operation blocking is not possible, block the besluiten module's GraphQL types entirely and block the document-content query.

CVSS Base Scores

version 4.0
version 3.1