CVE-2025-61138
Qlik Sense vulnerability analysis and mitigation

Overview

CVE-2025-61138 is an information disclosure vulnerability in Qlik Sense Enterprise v14.212.13, caused by unauthenticated access to the /dev-hub/ development panel directory. Discovered in April 2025 by researcher Israel A and publicly disclosed in October 2025, the flaw allows remote attackers to access development information and API token connections without any authentication. It carries a CVSS v3.1 base score of 7.5 (High) (Feedly, GitHub Gist).

Technical details

The root cause is classified as CWE-538 (Insertion of Sensitive Information into Externally-Accessible File or Directory). The /dev-hub/ directory in Qlik Sense Enterprise is exposed to the internet and authenticates via an anonymous session token, effectively bypassing all standard user login requirements. An attacker can simply navigate to https://[target]/dev-hub/ in a browser with no credentials to access the development panel, which may expose API tokens and internal development data. The researcher noted this exposure was identified across multiple internet-facing portals running the same product version, and that the related RCE vulnerability CVE-2024-55580 was patched but this exposure was not addressed (GitHub Gist).

Impact

Successful exploitation allows unauthenticated remote attackers to access the Qlik Sense development hub, potentially exposing API tokens, internal application configurations, and development-related sensitive information. The confidentiality impact is rated High, with no integrity or availability impact. Exposed API tokens could be leveraged for further unauthorized access to connected data sources or downstream systems, increasing the risk of lateral movement within an organization's data infrastructure (Feedly, GitHub Gist).

Exploitability

The vulnerability requires no authentication, no user interaction, and is exploitable remotely over the network, making it trivially easy to exploit. A proof-of-concept repository was created by the discoverer (temporarily restricted at time of disclosure). The EPSS score is approximately 0.018%, indicating low current exploitation probability. No evidence of active in-the-wild exploitation or CISA KEV catalog listing has been reported as of the time of this report (Feedly, GitHub Gist).

Exploitation steps

  1. Reconnaissance: Use tools such as Shodan, Censys, or Google dorks to identify internet-facing Qlik Sense Enterprise instances, specifically searching for the /dev-hub/ path or Qlik-specific HTTP response headers.
  2. Access the exposed endpoint: Navigate directly to https://[target]/dev-hub/ in a browser or via a tool like curl. No authentication prompt will appear; access is granted via an anonymous session token automatically.
  3. Enumerate development panel contents: Browse the development hub interface to identify exposed API tokens, application configurations, extension details, and any other development artifacts visible without authentication.
  4. Harvest API tokens: Extract any API tokens or connection strings visible in the panel, which may be used to authenticate against Qlik APIs or connected data sources for further unauthorized access (GitHub Gist).

Indicators of compromise

  • Network: Unexpected or repeated HTTP GET requests to /dev-hub/ or sub-paths from external/untrusted IP addresses in web server access logs.
  • Logs: Web server or Qlik Sense access logs showing anonymous session token usage originating from external IP ranges accessing /dev-hub/; absence of standard authentication headers in requests to this endpoint.
  • Network: Outbound connections from the Qlik Sense server to unfamiliar external hosts following access to the /dev-hub/ endpoint, potentially indicating API token abuse.

Mitigation and workarounds

The recommended workaround, as confirmed by the environment administrator and the researcher, is to remove /dev-hub/ from external DNS resolution to prevent internet-facing access. Additionally, organizations should enforce authentication on the /dev-hub/ endpoint and restrict access to internal networks only via firewall rules or reverse proxy configuration. Rotating any API tokens that may have been exposed through this endpoint is strongly advised. No vendor patch specifically addressing this exposure has been publicly announced; organizations should contact Qlik support and monitor for official advisories (GitHub Gist).

Community reactions

A Qlik representative (identified as "Bodgers") commented on the researcher's GitHub Gist in January 2026, requesting the full test case be submitted to SoftwareSecurityOffice@qlik.com, indicating the vendor was not fully aware of the issue at that time. The researcher confirmed they would submit the details. No broader media coverage or significant community discussion has been identified beyond the initial disclosure gist (GitHub Gist).

Additional resources


SourceThis report was generated using AI

Related Qlik Sense vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2023-48365CRITICAL9.9
  • Qlik Sense logoQlik Sense
  • cpe:2.3:a:qlik:qlik_sense
YesNoNov 15, 2023
CVE-2023-41265CRITICAL9.9
  • Qlik Sense logoQlik Sense
  • cpe:2.3:a:qlik:qlik_sense
YesNoAug 29, 2023
CVE-2025-61138HIGH7.5
  • Qlik Sense logoQlik Sense
  • cpe:2.3:a:qlik:qlik_sense
NoYesNov 20, 2025
CVE-2023-41266MEDIUM6.5
  • Qlik Sense logoQlik Sense
  • cpe:2.3:a:qlik:qlik_sense
YesNoAug 29, 2023
CVE-2021-36761MEDIUM5.3
  • Qlik Sense logoQlik Sense
  • cpe:2.3:a:qlik:qlik_sense
NoNoJun 21, 2022

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management