Severity Security Fixes for Qlik Sense Enterprise (CVE-2025-7783)

Published on 07.10.2025
News
BI-Blog

A security issue in Qlik Sense Enterprise has been identified, and patches have been made available.

Qlik Security Fix

Under the required conditions, an attacker could use the vulnerability to circumvent security controls in Qlik Sense. However, Qlik’s specific use of the form‑data library prevents these conditions from being met.

Affected Software 

All versions of Qlik Sense Enterprise for Windows prior to and including these releases are impacted: 

  • May 2025 Patch 6
  • November 2024 Patch 18
  • May 2024 Patch 24

Vulnerability Details (high)

Duo to improper input validation, a remote attacker with existing privileges is able to elevate them to the internal system role, which in turns allows them to execute commands on the server. 

Further Details

Solution 

Customers should upgrade Qlik Sense Enterprise to a version containing fixes for these issues. Fixes are available for the following versions: 

  • November 2023 Patch 18
  • February 2024 Patch 17
  • May 2024 Patch 25
  • November 2024 Patch 19
  • May 2025 Patch 7 

Leave a comment

Plain text

  • No HTML tags allowed.
  • Lines and paragraphs break automatically.
  • Web page addresses and email addresses turn into links automatically.