Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-6h3c-r723-7fx3 | NL Portal: IDOR allows any authenticated user to complete and tamper with another user's taak |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Tue, 15 Sep 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sun, 13 Sep 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Nl-portal
Nl-portal nl-portal-backend-libraries |
|
| Vendors & Products |
Nl-portal
Nl-portal nl-portal-backend-libraries |
Fri, 11 Sep 2026 23:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | NL Portal Backend Libraries provide backend components for Dutch government portals that interact with residents, customers, suppliers, and partner organizations. The `nl.nl-portal:taak` package from version 1.5.0 through 3.0.0 fails to verify ownership when processing the `submitTaakV2` GraphQL mutation, allowing an authenticated user who knows or guesses another user’s task ID to read its form data, overwrite its submitted data, and mark the task as completed. Version 3.0.1 contains a patch. As a workaround, block the `submitTaakV2` mutation at the API gateway or restrict the `/graphql` endpoint to trusted networks | |
| Title | NL Portal: IDOR allows any authenticated user to complete and tamper with another user's taak | |
| Weaknesses | CWE-639 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-09-15T16:36:50.488Z
Reserved: 2026-05-30T04:17:43.094Z
Link: CVE-2026-49464
Updated: 2026-09-15T16:36:44.115Z
Status : Received
Published: 2026-09-11T21:17:10.523
Modified: 2026-09-15T17:17:16.253
Link: CVE-2026-49464
No data.
OpenCVE Enrichment
Updated: 2026-09-15T20:15:14Z
Github GHSA