← Vulnerability feed

Vulnerability record · CVE-2023-41265 · published 29 August 2023

CVE-2023-41265: Qlik Sense Enterprise HTTP request tunneling privilege escalation

Qlik · Qlik Sense

Qlik Sense Enterprise for Windows fails to properly handle raw HTTP requests, allowing request tunneling that reaches the backend repository application. A remote attacker with a low-privileged account can abuse this to elevate privileges and execute requests on the backend server. The flaw affects multiple 2022 and 2023 release branches and is fixed in the August 2023 IR and later patches.

9.9 CVSS 3.1 Critical CISA KEV since 7 Dec 2023 Known ransomware use EPSS 88% · top 0.2% CWE-444 · HTTP request smuggling
9.9CVSS 3.1 base score
88%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
5References
5 Aug 2026Last modified by NVD

Description

An HTTP Request Tunneling vulnerability found in Qlik Sense Enterprise for Windows for versions May 2023 Patch 3 and earlier, February 2023 Patch 7 and earlier, November 2022 Patch 10 and earlier, and August 2022 Patch 12 and earlier allows a remote attacker to elevate their privilege by tunneling HTTP requests in the raw HTTP request. This allows them to send requests that get executed by the backend server hosting the repository application. This is fixed in August 2023 IR, May 2023 Patch 4, February 2023 Patch 8, November 2022 Patch 11, and August 2022 Patch 13.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityCVSS 9.9, CISA KEV listing with known ransomware use, and very high EPSS probability make this an urgent patch-first issue.

What it is

Qlik Sense Enterprise for Windows fails to properly handle raw HTTP requests, allowing request tunneling that reaches the backend repository application. A remote attacker with a low-privileged account can abuse this to elevate privileges and execute requests on the backend server. The flaw affects multiple 2022 and 2023 release branches and is fixed in the August 2023 IR and later patches.

Impact

An attacker gains elevated privileges and can execute arbitrary requests against the backend repository service, potentially leading to full compromise of the Qlik Sense environment. Because the scope is changed, impact extends beyond the initially accessed component.

Attack surface

Reachable over the network via crafted raw HTTP requests to the Qlik Sense Enterprise web endpoint. The CVSS vector indicates low privileges are required and no user interaction is needed.

Exploitation

Listed in CISA KEV with known ransomware campaign use and a 30-day EPSS probability of roughly 0.88, indicating active exploitation in the wild. Vendor advisory and US government references confirm the issue is being tracked as exploited.

What to do

  • Apply the vendor fix: upgrade to August 2023 IR, May 2023 Patch 4, February 2023 Patch 8, November 2022 Patch 11, or August 2022 Patch 13, or later.
  • If immediate patching is not possible, follow Qlik's mitigation guidance or discontinue use of the affected product per CISA KEV required action.
  • Restrict network access to Qlik Sense Enterprise endpoints to trusted users and networks.
  • Audit and reduce the number of low-privileged accounts that can reach the Qlik Sense web interface.
  • Monitor for and block anomalous raw HTTP requests containing tunneling patterns at the reverse proxy or WAF.

Detection

  • Inspect web and proxy logs for malformed or double-encoded HTTP requests and unusual absolute-form request lines targeting Qlik Sense.
  • Alert on requests to Qlik Sense backend repository endpoints originating from the web tier outside normal application behavior.
  • Correlate Qlik Sense authentication logs for low-privileged accounts performing actions or reaching endpoints beyond their role.
  • Hunt for post-exploitation activity such as new administrative accounts, unexpected repository service calls, or ransomware precursor behavior on Qlik Sense hosts.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2023-41265 to the Known Exploited Vulnerabilities catalog on 7 December 2023 as "Qlik Sense HTTP Tunneling Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable. Federal deadline 28 December 2023.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-41265 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.9CVE-2023-48365Qlik Sense Enterprise HTTP Request Smuggling Enables Unauthenticated RCEQlik Sense Enterprise for Windows before August 2023 Patch 2 fails to properly validate HTTP headers, allowing HTTP request tunneling to the backend …KEVEPSS 47%analysed6.5CVE-2023-41266Qlik Sense Enterprise path traversal enables anonymous sessionsQlik Sense Enterprise for Windows contains a path traversal flaw (CWE-22) in multiple releases up to the listed patch levels. An unauthenticated remo…KEVEPSS 85%analysed7.5CVE-2025-61138Qlik sense vulnerabilityQlik Sense Enterprise v14.212.13 was discovered to contain an information leak via the /dev-hub/ directory.EPSS 0.29%6.5CVE-2019-11628Qlikview server expression language injection vulnerabilityAn issue was discovered in QlikView Server before 11.20 SR19, 12.00 and 12.10 before 12.10 SR11, 12.20 before SR9, and 12.30 before SR2; and Qlik Sen…EPSS 0.97%5.3CVE-2021-36761Qlik sense server-side request forgery (ssrf) vulnerabilityThe GeoAnalytics feature in Qlik Sense April 2020 patch 4 allows SSRF.EPSS 1.2%5.3CVE-2022-0564Qlik sense observable discrepancy vulnerabilityA vulnerability in Qlik Sense Enterprise on Windows could allow an remote attacker to enumerate domain user accounts. An attacker could exploit this …EPSS 1.4%6.5CVE-2026-48710Starlette Host header validation flaw enables request.url path mismatchStarlette before 1.0.1 did not validate the HTTP Host header before using it to rebuild request.url, so a malformed Host value could make request.url…KEVEPSS 7.1%analysed7.5CVE-2025-61884Oracle E-Business Suite Configurator pre-auth data exposure flawOracle Configurator in Oracle E-Business Suite 12.2.3 through 12.2.14 exposes a vulnerability reachable over HTTP without authentication. A successfu…KEVEPSS 96%analysed

Source: NIST National Vulnerability Database (record CVE-2023-41265), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.