CVE-2026-49464High· 8.1▾ TwilightNL Portal Backend Libraries provide backend components for Dutch government portals that interact with residents, customers, suppliers, and partner organizations. The `nl.nl-portal:taak` package from version 1.5.0 through 3.0.0 fails to …
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 44.6 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Exploit-prediction probability, daily snapshots since Sep 12.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.2%
Last analysed / modified upstream
NL Portal Backend Libraries provide backend components for Dutch government portals that interact with residents, customers, suppliers, and partner organizations. The nl.nl-portal:taak package from version 1.5.0 through 3.0.0 fails to verify ownership when processing the submitTaakV2 GraphQL mutation, allowing an authenticated user who knows or guesses another user’s task ID to read its form data, overwrite its submitted data, and mark the task as completed. Version 3.0.1 contains a patch. As a workaround, block the submitTaakV2 mutation at the API gateway or restrict the /graphql endpoint to trusted networks
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Affected packages:
nl.nl-portal:taak >= 1.5.0, <= 3.0.0Patched in:
nl.nl-portal:taak 3.0.1Connected by shared product, vendor, weakness, or advisory.
CVE-2026-54683Medium· 6.5NL Portal Backend Libraries: Document contents remained downloadable by any logged-in user (incomplete fix of CVE-2026-49463)
CVE-2026-49463Medium· 6.5NL Portal: Missing per-user authorization on document and decision GraphQL queries in nl-portal-backend-libraries
CVE-2026-49462Medium· 5.3NL Portal Backend Libraries provide backend components for Dutch government portals that interact with residents, customers, suppliers, and partner organizations
CVE-2026-54050Medium· 6.5Sakai is a Collaboration and Learning Environment (CLE)
CVE-2021-46416High· 8.1Insecure direct object reference in SUNNY TRIPOWER 5.0 Firmware version 3.10.16.R leads to unauthorized user groups accessing due to insecure cookie handling.
CVE-2025-14459High· 8.5A flaw was found in KubeVirt Containerized Data Importer (CDI)