CVE-2023-41265
A critical flaw in Qlik Sense Enterprise for Windows lets a remote attacker send specially crafted HTTP requests that are executed by the backend server, giving the attacker elevated privileges. The issue affects versions up to August 2022 Patch 12, February 2023 Patch 7, November 2022 Patch 10, and May 2023 Patch 3. The vendor has released patches that fix the problem.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Qlik Sense Enterprise for Windows, versions May 2023 Patch 3 and earlier, February 2023 Patch 7 and earlier, November 2022 Patch 10 and earlier, and August 2022 Patch 12 and earlier. Administrators and users of these installations.
Real-world impact
An attacker can gain higher privileges on the Qlik Sense server, allowing them to run arbitrary commands or access sensitive data by sending tunneled HTTP requests.
Why this severity
The CVSS score of 9.6 reflects that the attack can be launched over the network, requires only low effort, needs minimal privileges, and has no user interaction. The vulnerability changes the scope of the affected component and can compromise confidentiality and integrity, but does not affect availability.
What to do about it
- 01Determine the current Qlik Sense Enterprise for Windows version.
- 02Download the appropriate patch (August 2023 IR, May 2023 Patch 4, February 2023 Patch 8, November 2022 Patch 11, or August 2022 Patch 13) from the vendor.
- 03Apply the patch following Qlik’s installation instructions.
- 04Restart Qlik Sense services and verify the patch is applied.
NVD-referenced vendor advisory
Timeline
- Aug 29, 2023 · Aug 29, 2023PublishedDisclosed and added to the National Vulnerability Database.
- Dec 7, 2023 · Dec 7, 2023Confirmed exploited (CISA KEV)CISA added it to the Known Exploited Vulnerabilities catalog — attackers are using it in the wild.
- Dec 28, 2023 · Dec 28, 2023CISA remediation deadlineFederal agencies are required to remediate by this date.
- Aug 5, 2026 · 1d agoAdvisory updatedThe NVD record was last revised.
- Aug 5, 2026 · 1d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.
How it’s attacked
References & advisories
- community.qlik.com/t5/Official-Support-Article…vendor advisory
- community.qlik.com/t5/Release-Notes/tkb-p/Rele…release notes
- cisa.gov/known-exploited-vulnerabili…us government resource