
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-61138 is an information disclosure vulnerability in Qlik Sense Enterprise v14.212.13, caused by unauthenticated access to the /dev-hub/ development panel directory. Discovered in April 2025 by researcher Israel A and publicly disclosed in October 2025, the flaw allows remote attackers to access development information and API token connections without any authentication. It carries a CVSS v3.1 base score of 7.5 (High) (Feedly, GitHub Gist).
The root cause is classified as CWE-538 (Insertion of Sensitive Information into Externally-Accessible File or Directory). The /dev-hub/ directory in Qlik Sense Enterprise is exposed to the internet and authenticates via an anonymous session token, effectively bypassing all standard user login requirements. An attacker can simply navigate to https://[target]/dev-hub/ in a browser with no credentials to access the development panel, which may expose API tokens and internal development data. The researcher noted this exposure was identified across multiple internet-facing portals running the same product version, and that the related RCE vulnerability CVE-2024-55580 was patched but this exposure was not addressed (GitHub Gist).
Successful exploitation allows unauthenticated remote attackers to access the Qlik Sense development hub, potentially exposing API tokens, internal application configurations, and development-related sensitive information. The confidentiality impact is rated High, with no integrity or availability impact. Exposed API tokens could be leveraged for further unauthorized access to connected data sources or downstream systems, increasing the risk of lateral movement within an organization's data infrastructure (Feedly, GitHub Gist).
The vulnerability requires no authentication, no user interaction, and is exploitable remotely over the network, making it trivially easy to exploit. A proof-of-concept repository was created by the discoverer (temporarily restricted at time of disclosure). The EPSS score is approximately 0.018%, indicating low current exploitation probability. No evidence of active in-the-wild exploitation or CISA KEV catalog listing has been reported as of the time of this report (Feedly, GitHub Gist).
/dev-hub/ path or Qlik-specific HTTP response headers.https://[target]/dev-hub/ in a browser or via a tool like curl. No authentication prompt will appear; access is granted via an anonymous session token automatically./dev-hub/ or sub-paths from external/untrusted IP addresses in web server access logs./dev-hub/; absence of standard authentication headers in requests to this endpoint./dev-hub/ endpoint, potentially indicating API token abuse.The recommended workaround, as confirmed by the environment administrator and the researcher, is to remove /dev-hub/ from external DNS resolution to prevent internet-facing access. Additionally, organizations should enforce authentication on the /dev-hub/ endpoint and restrict access to internal networks only via firewall rules or reverse proxy configuration. Rotating any API tokens that may have been exposed through this endpoint is strongly advised. No vendor patch specifically addressing this exposure has been publicly announced; organizations should contact Qlik support and monitor for official advisories (GitHub Gist).
A Qlik representative (identified as "Bodgers") commented on the researcher's GitHub Gist in January 2026, requesting the full test case be submitted to SoftwareSecurityOffice@qlik.com, indicating the vendor was not fully aware of the issue at that time. The researcher confirmed they would submit the details. No broader media coverage or significant community discussion has been identified beyond the initial disclosure gist (GitHub Gist).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."