← Vulnerability feed

Vulnerability record · CVE-2023-41266 · published 29 August 2023

CVE-2023-41266: Qlik Sense Enterprise path traversal enables anonymous sessions

Qlik · Qlik Sense

Qlik Sense Enterprise for Windows contains a path traversal flaw (CWE-22) in multiple releases up to the listed patch levels. An unauthenticated remote attacker can abuse it to generate an anonymous session and then send HTTP requests to endpoints that should require authorization. It is listed in CISA KEV with known ransomware campaign use, so it warrants urgent attention despite a medium CVSS score.

6.5 CVSS 3.1 Medium CISA KEV since 7 Dec 2023 Known ransomware use EPSS 85% · top 0.3% CWE-22 · Path traversal
6.5CVSS 3.1 base score
85%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
5References
5 Aug 2026Last modified by NVD

Description

A path traversal vulnerability found in Qlik Sense Enterprise for Windows for versions May 2023 Patch 3 and earlier, February 2023 Patch 7 and earlier, November 2022 Patch 10 and earlier, and August 2022 Patch 12 and earlier allows an unauthenticated remote attacker to generate an anonymous session. This allows them to transmit HTTP requests to unauthorized endpoints. This is fixed in August 2023 IR, May 2023 Patch 4, February 2023 Patch 8, November 2022 Patch 11, and August 2022 Patch 13.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityAlthough CVSS is medium (6.5), the flaw is unauthenticated and network-reachable, is in CISA KEV with known ransomware campaign use, and has a very high EPSS probability.

What it is

Qlik Sense Enterprise for Windows contains a path traversal flaw (CWE-22) in multiple releases up to the listed patch levels. An unauthenticated remote attacker can abuse it to generate an anonymous session and then send HTTP requests to endpoints that should require authorization. It is listed in CISA KEV with known ransomware campaign use, so it warrants urgent attention despite a medium CVSS score.

Impact

An attacker gains an anonymous session and can reach unauthorized HTTP endpoints, giving low-level confidentiality and integrity impact within the Qlik Sense deployment. KEV listing indicates real-world use, including in ransomware campaigns.

Attack surface

Reachable over the network with no authentication and no user interaction required, per the CVSS vector AV:N/AC:L/PR:N/UI:N. The flaw is in the Qlik Sense Enterprise for Windows web/service layer and is triggered by crafted HTTP requests.

Exploitation

CVE-2023-41266 is in CISA KEV (added 2023-12-07, due 2023-12-28) with known ransomware campaign use, and EPSS 30-day probability is 0.84843 (99.7th percentile), indicating active exploitation. No public exploit code details are provided in the record.

What to do

  • Apply the vendor fixes: August 2023 IR, May 2023 Patch 4, February 2023 Patch 8, November 2022 Patch 11, or August 2022 Patch 13, whichever matches your branch.
  • If patching cannot be completed immediately, follow the vendor advisory and CISA KEV required action, including discontinuing use if no remediation is available.
  • Restrict network exposure of Qlik Sense Enterprise for Windows to trusted networks and block direct internet access to its HTTP endpoints.
  • Monitor and review anonymous session creation and access to endpoints that should require authentication.
  • Verify no unauthorized sessions or endpoint access occurred before patching, given known ransomware use.

Detection

  • Alert on anonymous session creation events in Qlik Sense logs, especially from unexpected source IPs.
  • Hunt for HTTP requests containing path traversal sequences (../, encoded variants) targeting Qlik Sense endpoints.
  • Correlate Qlik Sense access logs with endpoint paths that normally require authentication.
  • Review for post-exploitation activity consistent with ransomware staging on hosts running Qlik Sense Enterprise for Windows.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2023-41266 to the Known Exploited Vulnerabilities catalog on 7 December 2023 as "Qlik Sense Path Traversal Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable. Federal deadline 28 December 2023.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-41266 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.9CVE-2023-48365Qlik Sense Enterprise HTTP Request Smuggling Enables Unauthenticated RCEQlik Sense Enterprise for Windows before August 2023 Patch 2 fails to properly validate HTTP headers, allowing HTTP request tunneling to the backend …KEVEPSS 47%analysed9.9CVE-2023-41265Qlik Sense Enterprise HTTP request tunneling privilege escalationQlik Sense Enterprise for Windows fails to properly handle raw HTTP requests, allowing request tunneling that reaches the backend repository applicat…KEVEPSS 88%analysed7.5CVE-2025-61138Qlik sense vulnerabilityQlik Sense Enterprise v14.212.13 was discovered to contain an information leak via the /dev-hub/ directory.EPSS 0.29%6.5CVE-2019-11628Qlikview server expression language injection vulnerabilityAn issue was discovered in QlikView Server before 11.20 SR19, 12.00 and 12.10 before 12.10 SR11, 12.20 before SR9, and 12.30 before SR2; and Qlik Sen…EPSS 0.97%5.3CVE-2021-36761Qlik sense server-side request forgery (ssrf) vulnerabilityThe GeoAnalytics feature in Qlik Sense April 2020 patch 4 allows SSRF.EPSS 1.2%5.3CVE-2022-0564Qlik sense observable discrepancy vulnerabilityA vulnerability in Qlik Sense Enterprise on Windows could allow an remote attacker to enumerate domain user accounts. An attacker could exploit this …EPSS 1.4%9.8CVE-2026-93616Checkpoint multi-domain security management path traversal vulnerabilityA directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute arbitrary scripts on Check Point Managem…KEVEPSS 20%10.0CVE-2026-85706GitLab CE/EE repository commits API path traversal allows unauthenticated file readGitLab CE/EE contains improper path confinement and missing authentication enforcement in the repository commits API, allowing an unauthenticated use…KEVEPSS 91%analysed

Source: NIST National Vulnerability Database (record CVE-2023-41266), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.