Back to search
CVE-2025-34140
Published: Jul 22, 2025
Modified: May 25, 2026
PUBLISHED
Description
An authorization bypass vulnerability exists in ETQ Reliance (legacy CG and NXG SaaS platforms). By appending a specific URI suffix to certain API endpoints, an unauthenticated attacker can bypass access control checks and retrieve limited sensitive resources. The root cause was a misconfiguration in API authorization logic, which has since been corrected in SE.2025.1 and 2025.1.2.
| Vendor | Product | Versions |
|---|---|---|
ETQ | Reliance CG (legacy) | affected 0 - < SE.2025.1unaffected SE.2025.1 |
ETQ | Reliance NXG (SaaS) | affected 0 - < 2025.1.2unaffected 2025.1.2 |
Weaknesses (CWE)
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now