Vulnerability record · CVE-2023-41265 · published 29 August 2023
CVE-2023-41265: Qlik Sense Enterprise HTTP request tunneling privilege escalation
Qlik · Qlik Sense
Qlik Sense Enterprise for Windows fails to properly handle raw HTTP requests, allowing request tunneling that reaches the backend repository application. A remote attacker with a low-privileged account can abuse this to elevate privileges and execute requests on the backend server. The flaw affects multiple 2022 and 2023 release branches and is fixed in the August 2023 IR and later patches.
Description
An HTTP Request Tunneling vulnerability found in Qlik Sense Enterprise for Windows for versions May 2023 Patch 3 and earlier, February 2023 Patch 7 and earlier, November 2022 Patch 10 and earlier, and August 2022 Patch 12 and earlier allows a remote attacker to elevate their privilege by tunneling HTTP requests in the raw HTTP request. This allows them to send requests that get executed by the backend server hosting the repository application. This is fixed in August 2023 IR, May 2023 Patch 4, February 2023 Patch 8, November 2022 Patch 11, and August 2022 Patch 13.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.9, CISA KEV listing with known ransomware use, and very high EPSS probability make this an urgent patch-first issue.
What it is
Qlik Sense Enterprise for Windows fails to properly handle raw HTTP requests, allowing request tunneling that reaches the backend repository application. A remote attacker with a low-privileged account can abuse this to elevate privileges and execute requests on the backend server. The flaw affects multiple 2022 and 2023 release branches and is fixed in the August 2023 IR and later patches.
Impact
An attacker gains elevated privileges and can execute arbitrary requests against the backend repository service, potentially leading to full compromise of the Qlik Sense environment. Because the scope is changed, impact extends beyond the initially accessed component.
Attack surface
Reachable over the network via crafted raw HTTP requests to the Qlik Sense Enterprise web endpoint. The CVSS vector indicates low privileges are required and no user interaction is needed.
Exploitation
Listed in CISA KEV with known ransomware campaign use and a 30-day EPSS probability of roughly 0.88, indicating active exploitation in the wild. Vendor advisory and US government references confirm the issue is being tracked as exploited.
What to do
- Apply the vendor fix: upgrade to August 2023 IR, May 2023 Patch 4, February 2023 Patch 8, November 2022 Patch 11, or August 2022 Patch 13, or later.
- If immediate patching is not possible, follow Qlik's mitigation guidance or discontinue use of the affected product per CISA KEV required action.
- Restrict network access to Qlik Sense Enterprise endpoints to trusted users and networks.
- Audit and reduce the number of low-privileged accounts that can reach the Qlik Sense web interface.
- Monitor for and block anomalous raw HTTP requests containing tunneling patterns at the reverse proxy or WAF.
Detection
- Inspect web and proxy logs for malformed or double-encoded HTTP requests and unusual absolute-form request lines targeting Qlik Sense.
- Alert on requests to Qlik Sense backend repository endpoints originating from the web tier outside normal application behavior.
- Correlate Qlik Sense authentication logs for low-privileged accounts performing actions or reaching endpoints beyond their role.
- Hunt for post-exploitation activity such as new administrative accounts, unexpected repository service calls, or ransomware precursor behavior on Qlik Sense hosts.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2023-41265 to the Known Exploited Vulnerabilities catalog on 7 December 2023 as "Qlik Sense HTTP Tunneling Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable. Federal deadline 28 December 2023.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2023-41265 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-41265), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.