Authorization Bypass in ETQ Reliance by ETQ
CVE-2025-34140
8.7HIGH
Key Information:
- Vendor
Etq
- Vendor
- CVE Published:
- 22 July 2025
What is CVE-2025-34140?
An authorization bypass vulnerability has been identified in the ETQ Reliance SaaS platforms (legacy CG and NXG). This issue allows unauthenticated attackers to bypass access controls by appending certain URI suffixes to specific API endpoints, enabling them to retrieve limited sensitive resources. The vulnerability resulted from a misconfiguration in the API authorization logic. Remediation has been implemented in the subsequent versions, SE.2025.1 and SE.2025.1.2, which address this security issue effectively.
Affected Version(s)
Reliance CG (legacy) *
Reliance NXG (SaaS) *
Reliance NXG (SaaS) * < 2025.1.2