CVE-2026-49462: nl.nl-portal:app has GraphiQL UI and GraphQL schema introspection enabled by default
NL Portal Backend Libraries provide backend components for Dutch government portals that interact with residents, customers, suppliers, and partner organizations. In versions up to and including 3.0.0, deployments using the shipped default configuration exposed two GraphQL developer features without requiring authentication: the GraphiQL playground, an interactive UI for issuing GraphQL queries; and schema introspection, which lets a caller download the full description of every query, mutation, type, and argument the API supports. Anyone who could reach the /graphiql endpoint could open the playground in a browser, pull the full schema, and use that to map out the API and craft calls against it. By itself this does not leak user data, but it removes the guesswork from attacking the rest of the API and significantly lowers the bar for finding and exploiting other weaknesses. Version 3.0.1 patches the issue. As a workaround, override the two settings in deployed configuration.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
nl.nl-portal:appto a version that resolves this vulnerability.Fixed in 3.0.1 - Configuration
Override the two deployed configuration settings so GraphiQL playground and schema introspection are no longer exposed without authentication.
nl.nl-portal:app GraphiQL UI and GraphQL schema introspection = override deployed configuration to disable both developer features (GraphiQL playground and schema introspection)
Event History
Frequently Asked Questions
Which deployments are exposed?
Deployments of nl.nl-portal:app through version 3.0.0 are exposed if they use the shipped default configuration and an unauthenticated party can reach the /graphiql endpoint.
Does an attacker need credentials or user interaction?
No. The exposed GraphiQL UI and schema introspection are available without authentication, and an attacker only needs network access to the /graphiql endpoint.
What can an attacker obtain through this issue?
An attacker can use the browser-based playground to retrieve the full GraphQL schema, including supported queries, mutations, types, and arguments. The issue does not itself expose user data, but it can help an attacker identify and craft calls targeting other API weaknesses.
What should be done if upgrading is not immediately possible?
Override the two relevant settings in the deployed configuration to disable the GraphiQL playground and GraphQL schema introspection. Version 3.0.1 patches the issue.