Vulnerability record · CVE-2023-41266 · published 29 August 2023
CVE-2023-41266: Qlik Sense Enterprise path traversal enables anonymous sessions
Qlik · Qlik Sense
Qlik Sense Enterprise for Windows contains a path traversal flaw (CWE-22) in multiple releases up to the listed patch levels. An unauthenticated remote attacker can abuse it to generate an anonymous session and then send HTTP requests to endpoints that should require authorization. It is listed in CISA KEV with known ransomware campaign use, so it warrants urgent attention despite a medium CVSS score.
Description
A path traversal vulnerability found in Qlik Sense Enterprise for Windows for versions May 2023 Patch 3 and earlier, February 2023 Patch 7 and earlier, November 2022 Patch 10 and earlier, and August 2022 Patch 12 and earlier allows an unauthenticated remote attacker to generate an anonymous session. This allows them to transmit HTTP requests to unauthorized endpoints. This is fixed in August 2023 IR, May 2023 Patch 4, February 2023 Patch 8, November 2022 Patch 11, and August 2022 Patch 13.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Automated analysis
critical priorityAlthough CVSS is medium (6.5), the flaw is unauthenticated and network-reachable, is in CISA KEV with known ransomware campaign use, and has a very high EPSS probability.
What it is
Qlik Sense Enterprise for Windows contains a path traversal flaw (CWE-22) in multiple releases up to the listed patch levels. An unauthenticated remote attacker can abuse it to generate an anonymous session and then send HTTP requests to endpoints that should require authorization. It is listed in CISA KEV with known ransomware campaign use, so it warrants urgent attention despite a medium CVSS score.
Impact
An attacker gains an anonymous session and can reach unauthorized HTTP endpoints, giving low-level confidentiality and integrity impact within the Qlik Sense deployment. KEV listing indicates real-world use, including in ransomware campaigns.
Attack surface
Reachable over the network with no authentication and no user interaction required, per the CVSS vector AV:N/AC:L/PR:N/UI:N. The flaw is in the Qlik Sense Enterprise for Windows web/service layer and is triggered by crafted HTTP requests.
Exploitation
CVE-2023-41266 is in CISA KEV (added 2023-12-07, due 2023-12-28) with known ransomware campaign use, and EPSS 30-day probability is 0.84843 (99.7th percentile), indicating active exploitation. No public exploit code details are provided in the record.
What to do
- Apply the vendor fixes: August 2023 IR, May 2023 Patch 4, February 2023 Patch 8, November 2022 Patch 11, or August 2022 Patch 13, whichever matches your branch.
- If patching cannot be completed immediately, follow the vendor advisory and CISA KEV required action, including discontinuing use if no remediation is available.
- Restrict network exposure of Qlik Sense Enterprise for Windows to trusted networks and block direct internet access to its HTTP endpoints.
- Monitor and review anonymous session creation and access to endpoints that should require authentication.
- Verify no unauthorized sessions or endpoint access occurred before patching, given known ransomware use.
Detection
- Alert on anonymous session creation events in Qlik Sense logs, especially from unexpected source IPs.
- Hunt for HTTP requests containing path traversal sequences (../, encoded variants) targeting Qlik Sense endpoints.
- Correlate Qlik Sense access logs with endpoint paths that normally require authentication.
- Review for post-exploitation activity consistent with ransomware staging on hosts running Qlik Sense Enterprise for Windows.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2023-41266 to the Known Exploited Vulnerabilities catalog on 7 December 2023 as "Qlik Sense Path Traversal Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable. Federal deadline 28 December 2023.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2023-41266 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-41266), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.