---
id: CVE-2023-41266
title: >-
  A path traversal vulnerability found in Qlik Sense Enterprise for Windows for
  versions May 2023 Patch 3 and earlier, February 2023 Patch 7 and earlier,
  November 2022 Patch 10 and earlier, and August 2022 Patch 12 and earlier
  allows an un…
summary: >-
  A path traversal vulnerability found in Qlik Sense Enterprise for Windows for
  versions May 2023 Patch 3 and earlier, February 2023 Patch 7 and earlier,
  November 2022 Patch 10 and earlier, and August 2022 Patch 12 and earlier
  allows an un…
severity: high
cvss: 8.2
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N'
cwe:
  - CWE-22
  - CWE-22
vendor: qlik
product: qlik_sense
affected:
  - qlik_sense = august_2022
  - qlik_sense = february_2023
  - qlik_sense = may_2023
  - qlik_sense = november_2022
published: '2023-08-29'
updated: '2026-08-05'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2023-41266'
references:
  - url: >-
      https://community.qlik.com/t5/Official-Support-Articles/Critical-Security-fixes-for-Qlik-Sense-Enterprise-for-Windows/ta-p/2110801
    label: cve@mitre.org
  - url: 'https://community.qlik.com/t5/Release-Notes/tkb-p/ReleaseNotes'
    label: cve@mitre.org
  - url: >-
      https://community.qlik.com/t5/Official-Support-Articles/Critical-Security-fixes-for-Qlik-Sense-Enterprise-for-Windows/ta-p/2110801
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://community.qlik.com/t5/Release-Notes/tkb-p/ReleaseNotes'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-41266
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - kev
  - in-the-wild
  - exploit-available
epss: 0.84843
epssPercentile: 0.997
kev: true
kevDateAdded: '2023-12-07'
kevDueDate: '2023-12-28'
kevRansomware: true
exploited: true
ingestedAt: '2026-08-05T05:45:57.651Z'
exploits:
  nuclei:
    - CVE-2023-41266
  checkedAt: '2026-09-24T07:52:50.058Z'
exploitAvailable: true
---

## Overview

A path traversal vulnerability found in Qlik Sense Enterprise for Windows for versions May 2023 Patch 3 and earlier, February 2023 Patch 7 and earlier, November 2022 Patch 10 and earlier, and August 2022 Patch 12 and earlier allows an unauthenticated remote attacker to generate an anonymous session. This allows them to transmit HTTP requests to unauthorized endpoints. This is fixed in August 2023 IR, May 2023 Patch 4, February 2023 Patch 8, November 2022 Patch 11, and August 2022 Patch 13.

## Affected

- `qlik_sense = august_2022`
- `qlik_sense = february_2023`
- `qlik_sense = may_2023`
- `qlik_sense = november_2022`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
