AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2023-41266

HIGH · CVSS 8.2 EPSS 82.12% CISA KEV · Actively Exploited

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2023-08-29 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CISA KEV Details

Status: This CVE is listed in CISA's Known Exploited Vulnerabilities catalog.

Ransomware use: Known

Added to KEV: 2023-12-07

Required action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.

CVE
CVE-2023-41266
Severity
HIGH
CVSS
8.2
EPSS
82.12%
Windows

Original NVD Description

A path traversal vulnerability found in Qlik Sense Enterprise for Windows for versions May 2023 Patch 3 and earlier, February 2023 Patch 7 and earlier, November 2022 Patch 10 and earlier, and August 2022 Patch 12 and earlier allows an unauthenticated remote attacker to generate an anonymous session. This allows them to transmit HTTP requests to unauthorized endpoints. This is fixed in August 2023 IR, May 2023 Patch 4, February 2023 Patch 8, November 2022 Patch 11, and August 2022 Patch 13.

Related CVEs

Other vulnerabilities affecting the same vendor(s)