We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.
Please see our statement on Data Privacy.
An authorization bypass vulnerability exists in ETQ Reliance (legacy CG and NXG SaaS platforms). By appending a specific URI suffix to certain API endpoints, an unauthenticated attacker can bypass access control checks and retrieve limited sensitive resources. The root cause was a misconfiguration in API authorization logic, which has since been corrected in SE.2025.1 and 2025.1.2.
Reserved 2025-04-15 | Published 2025-07-22 | Updated 2025-07-22 | Assigner VulnCheckCWE-639 Authorization Bypass Through User-Controlled Key
Adam Kues and Shubham Shah of Assetnote
www.etq.com/product-overview/
www.etq.com/blog/etq-reliance-security-update/
Support options