CVE-2023-41265

CRITICAL KEV RANSOMWARE NUCLEI

Qlik Sense Enterprise for Windows <= May 2023 Patch 3 - HTTP Request Tunneling

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2023-41265 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added December 7, 2023, with confirmed use in ransomware campaigns. EIP tracks 1 public exploit from researchers including praetorian-inc. A Nuclei detection template is also available.

AI-analyzed exploit summary This repository contains a Nuclei template designed to detect the ZeroQlik vulnerability (CVE-2023-41265 and CVE-2023-41266) in Qlik Sense Enterprise for Windows. The template sends a crafted HTTP request to a specific endpoint and checks for a 400 status code along with specific response patterns to confirm the vulnerability.

Description

An HTTP Request Tunneling vulnerability found in Qlik Sense Enterprise for Windows for versions May 2023 Patch 3 and earlier, February 2023 Patch 7 and earlier, November 2022 Patch 10 and earlier, and August 2022 Patch 12 and earlier allows a remote attacker to elevate their privilege by tunneling HTTP requests in the raw HTTP request. This allows them to send requests that get executed by the backend server hosting the repository application. This is fixed in August 2023 IR, May 2023 Patch 4, February 2023 Patch 8, November 2022 Patch 11, and August 2022 Patch 13.

Exploits (1)

nomisec SCANNER 5 stars
by praetorian-inc · remote
https://github.com/praetorian-inc/zeroqlik-detect

This repository contains a Nuclei template designed to detect the ZeroQlik vulnerability (CVE-2023-41265 and CVE-2023-41266) in Qlik Sense Enterprise for Windows. The template sends a crafted HTTP request to a specific endpoint and checks for a 400 status code along with specific response patterns to confirm the vulnerability.

Classification
Scanner 90%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: Qlik Sense Enterprise for Windows
Auth required
Prerequisites: Access to the target Qlik Sense Enterprise instance · Valid session cookie (X-Qlik-Session)
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Nuclei Templates (1)

Qlik Sense Enterprise - HTTP Request Smuggling
CRITICALby AdamCrosser
Shodan: html:"Qlik" || http.favicon.hash:-74348711 || http.html:"qlik" || http.title:"qlik-sense"
FOFA: app="qlik-sense" || title="qlik-sense" || icon_hash=-74348711 || body="qlik"

Scores

CVSS v3 9.6
EPSS 0.8497
EPSS Percentile 99.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation active
Automatable yes
Technical Impact total

Details

CISA KEV 2023-12-07
VulnCheck KEV 2023-11-28
InTheWild.io 2023-11-28
ENISA EUVD EUVD-2023-45782
Ransomware Use Confirmed
CWE
CWE-444
Status published
Products (4)
qlik/qlik_sense august_2022 (13 CPE variants)
qlik/qlik_sense february_2023 (8 CPE variants)
qlik/qlik_sense may_2023 (4 CPE variants)
qlik/qlik_sense november_2022 (11 CPE variants)
Published Aug 29, 2023
KEV Added Dec 07, 2023
Tracked Since Feb 18, 2026