CVE-2023-41266

HIGH(8.2)KEVRansomwareLikely Exploited

Qlik Sense Path Traversal Vulnerability

Description

CVE-2023-41266 is a path traversal vulnerability (CWE-22) affecting Qlik Sense Enterprise for Windows across multiple patch versions up to and including May 2023 Patch 3, February 2023 Patch 7, November 2022 Patch 10, and August 2022 Patch 12. An unauthenticated remote attacker can exploit this vulnerability to generate an anonymous session, bypassing authentication controls and transmitting HTTP requests to unauthorized internal endpoints. CVE-2023-41266 is listed in the CISA Known Exploited Vulnerabilities (KEV) catalog as associated with ransomware activity, and its EPSS score of 0.943 places it in the 99th percentile of exploitation probability — making it one of the most critically urgent vulnerabilities to remediate in affected Qlik Sense environments.

KEV Information

Vendor
Qlik
Product
Sense
Date Added
December 7, 2023
Due Date
December 28, 2023
Required Action
Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.

CVSS Score

Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:NOpen in Calculator
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
LOW
Availability Impact
NONE
Exploitability Score
3.9
Impact Score
4.2

CWEs

Affected Products

VendorProductVersion
qlikqlik senseaugust_2022; february_2023; may_2023; november_2022

Multiple CVSS Assessments

Source: [email protected](Secondary)
8.2
HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N

Source: [email protected](Primary)
6.5
MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

References

Weakness Type

CWE-22: Improper Limitation of a Pathname to a Restricted Directory (Path Traversal)

CVE-2023-41266 is caused by a path traversal weakness in Qlik Sense Enterprise for Windows. The application fails to properly validate or restrict user-supplied path components, allowing an unauthenticated attacker to traverse directory boundaries and access resources or endpoints that should require authentication. In this case, the path traversal enables generation of an anonymous session that can be used to send requests to otherwise unauthorized endpoints.

Learn more: CWE-22 — Improper Limitation of a Pathname to a Restricted Directory

Impact Analysis

CVE-2023-41266 has a CVSS v3.1 base score of 8.2 (HIGH). The attack vector is Network, attack complexity is Low, no privileges are required, and no user interaction is needed. The vulnerability is remotely exploitable by any unauthenticated attacker.

Confidentiality Impact: High — Unauthorized access to internal endpoints and session generation can expose sensitive business data, reports, and credentials stored or accessible within Qlik Sense.

Integrity Impact: Low — Limited write capability; the primary impact is unauthorized read access rather than data modification.

Availability Impact: None — The vulnerability does not directly cause service disruption.

CVE-2023-41266 is often chained with CVE-2023-41265 (another Qlik Sense vulnerability) in documented attack chains, significantly amplifying the combined impact to enable remote code execution. The KEV listing with ransomware association underscores the severity of this vulnerability in real-world attack campaigns.

Exploit Maturity

CVE-2023-41266 is actively exploited in the wild and has been associated with ransomware campaigns. CISA added it to the Known Exploited Vulnerabilities (KEV) catalog with a remediation due date of December 28, 2023. The EPSS score of 0.943 places this CVE in the 99th percentile — among the very highest exploitation likelihoods of any published vulnerability. Threat actors have been observed chaining CVE-2023-41266 with related Qlik Sense vulnerabilities (notably CVE-2023-41265) to achieve unauthenticated remote code execution, with ransomware groups using the exploit chain as an initial access vector against enterprise analytics platforms.

Remediation

  1. Apply the vendor-released patches for Qlik Sense Enterprise for Windows immediately:
    • August 2023 IR (Initial Release) or later
    • May 2023 Patch 4 or later
    • February 2023 Patch 8 or later
    • November 2022 Patch 11 or later
    • August 2022 Patch 13 or later
  2. Restrict external network access to the Qlik Sense Enterprise server. If public internet access is not required, place the server behind a VPN or restrict access to known IP ranges.
  3. Review access logs for signs of exploitation — look for unusual anonymous session creation or unexpected requests to internal endpoints.
  4. Audit user accounts and permissions on the Qlik Sense platform for unauthorized changes that may indicate prior exploitation.
  5. Apply mitigations per vendor instructions as required by the CISA KEV catalog. Consult the Qlik community advisory for detailed patch application steps.
  6. Assess exposure to CVE-2023-41265 (a related Qlik Sense vulnerability often chained with CVE-2023-41266) and apply relevant patches concurrently.

Technical Details

CVE-2023-41266 is a path traversal vulnerability (CWE-22) in Qlik Sense Enterprise for Windows. The affected versions span multiple patch trains: May 2023 ≤ Patch 3, February 2023 ≤ Patch 7, November 2022 ≤ Patch 10, and August 2022 ≤ Patch 12.

Mechanism: The vulnerability exists in the HTTP request handling layer of Qlik Sense Enterprise. By manipulating URL path components with traversal sequences, an unauthenticated attacker can craft requests that bypass the application’s authentication checks. This allows the attacker to generate an anonymous session context, from which they can then send HTTP requests to internal API endpoints or application resources that would normally require authentication.

Chaining with CVE-2023-41265: Security researchers and threat actors documented an exploit chain where CVE-2023-41266 (authentication bypass via path traversal) is combined with CVE-2023-41265 (HTTP request tunneling) to achieve unauthenticated remote code execution on the Qlik Sense server. This chained attack has been attributed to ransomware operators targeting enterprise analytics platforms.

Fixed versions: August 2023 IR, May 2023 Patch 4, February 2023 Patch 8, November 2022 Patch 11, August 2022 Patch 13.

Frequently Asked Questions

What is CVE-2023-41266?

CVE-2023-41266 is a path traversal vulnerability in Qlik Sense Enterprise for Windows (multiple versions up to May 2023 Patch 3). An unauthenticated remote attacker can exploit it to generate an anonymous session and send HTTP requests to unauthorized internal endpoints.

Is CVE-2023-41266 associated with ransomware?

Yes. CVE-2023-41266 is listed in the CISA KEV catalog with a ransomware association. Threat actors have used this vulnerability — often chained with CVE-2023-41265 — as an initial access vector in ransomware attacks against enterprise Qlik Sense environments.

Which versions of Qlik Sense are affected by CVE-2023-41266?

Affected versions include May 2023 Patch 3 and earlier, February 2023 Patch 7 and earlier, November 2022 Patch 10 and earlier, and August 2022 Patch 12 and earlier. Fixed versions are August 2023 IR, May 2023 Patch 4, February 2023 Patch 8, November 2022 Patch 11, and August 2022 Patch 13.

How do I remediate CVE-2023-41266?

Apply the appropriate patched version of Qlik Sense Enterprise for Windows immediately. Additionally, restrict external network access to the Qlik Sense server, review logs for signs of prior exploitation, and check for related vulnerability CVE-2023-41265 which is frequently chained with this one.

CVSS Score

8.2
HIGH(8.2)

EPSS Score

EPSS Score82.12%
EPSS Percentile99.6%

Dates

PublishedAugust 29, 2023
Last ModifiedAugust 5, 2026
StatusAnalyzed
CVSS Versionv3.1

Need Help With Vulnerability Management?

Our security experts can help you prioritize and remediate vulnerabilities effectively.