CVE-2023-41266 is a path traversal vulnerability in Qlik Sense Enterprise for Windows that permits unauthenticated remote attackers to create an anonymous session and send HTTP requests to unauthorized endpoints. The proxy permits unauthenticated requests matching a font-loading path pattern but fails to normalize paths, allowing traversal sequences to reach internal REST endpoints while retaining the permitted pattern. Affected releases include May 2023 Patch 3 and earlier, February 2023 Patch 7 and earlier, November 2022 Patch 10 and earlier, and August 2022 Patch 12 and earlier. Chaining this authentication bypass with CVE-2023-41265 enables unauthenticated remote code execution; CVE-2023-41266 alone is not established as a code-execution vulnerability.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No valid public exploits. Mallory filtered out 1 candidate as fakes, detection scripts, or README-only repos.
All candidate exploits were filtered out by Mallory's validation.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Qlik Sense path traversal vulnerability that allows unauthenticated attackers to create anonymous sessions. It forms part of the ZeroQlik exploit chain with CVE-2023-41265, enabling execution under the Qlik Sense service account. The article attributes initial access in Cactus ransomware incidents to ZeroQlik and/or DoubleQlik, but notes that Qlik Sense logs cannot distinguish which exploit route was used.
A vulnerability in Qlik Sense exploited by Cactus ransomware for initial access.
A Qlik Sense Enterprise vulnerability that can enable an unauthenticated attacker to take over the system hosting Qlik Sense. It has reportedly been exploited, alone or in combination with the other listed flaws, to deploy ransomware.
A specific Qlik Sense vulnerability cited as being exploited by the Cactus ransomware group for initial access.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.