CVE Database
/

CVE-2025-34140

Back to search

CVE-2025-34140

Published: Jul 22, 2025

Modified: May 25, 2026

PUBLISHED

Description

An authorization bypass vulnerability exists in ETQ Reliance (legacy CG and NXG SaaS platforms). By appending a specific URI suffix to certain API endpoints, an unauthenticated attacker can bypass access control checks and retrieve limited sensitive resources. The root cause was a misconfiguration in API authorization logic, which has since been corrected in SE.2025.1 and 2025.1.2.

VendorProductVersions

ETQ

Reliance CG (legacy)

affected
0 - < SE.2025.1
unaffected
SE.2025.1

ETQ

Reliance NXG (SaaS)

affected
0 - < 2025.1.2
unaffected
2025.1.2

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now