An authorization bypass vulnerability exists in ETQ Reliance (legacy CG and NXG SaaS platforms). By appending a specific URI suffix to certain API endpoints, an unauthenticated attacker can bypass access control checks and retrieve limited sensitive resources. The root cause was a misconfiguration in API authorization logic, which has since been corrected in SE.2025.1 and 2025.1.2.
                
            Metrics
Affected Vendors & Products
References
        History
                    Tue, 22 Jul 2025 14:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | ssvc 
 | 
Tue, 22 Jul 2025 12:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | An authorization bypass vulnerability exists in ETQ Reliance (legacy CG and NXG SaaS platforms). By appending a specific URI suffix to certain API endpoints, an unauthenticated attacker can bypass access control checks and retrieve limited sensitive resources. The root cause was a misconfiguration in API authorization logic, which has since been corrected in SE.2025.1 and 2025.1.2. | |
| Title | ETQ Reliance CG/NXG API Authorization Bypass via ;localized-text URI Suffix | |
| Weaknesses | CWE-639 | |
| References |  | |
| Metrics | cvssV4_0 
 | 
 MITRE
                        MITRE
                    Status: PUBLISHED
Assigner: VulnCheck
Published: 2025-07-22T12:34:31.324Z
Updated: 2025-07-22T13:24:24.675Z
Reserved: 2025-04-15T19:15:22.563Z
Link: CVE-2025-34140
 Vulnrichment
                        Vulnrichment
                    Updated: 2025-07-22T13:23:45.898Z
 NVD
                        NVD
                    Status : Awaiting Analysis
Published: 2025-07-22T13:15:23.957
Modified: 2025-07-25T15:29:44.523
Link: CVE-2025-34140
 Redhat
                        Redhat
                    No data.