Path Traversal Vulnerability in Sage Employee Self Service
CVE-2026-67395

5.9MEDIUM

Key Information:

Vendor

Sage

Vendor
CVE Published:
1 September 2026

What is CVE-2026-67395?

A path traversal vulnerability exists in the custom logo functionality of Sage Employee Self Service due to inadequate validation of file path parameters. Attackers can exploit this flaw by using directory traversal sequences and their encoded variants to circumvent directory restrictions, potentially gaining access to files outside the application's designated file system areas. Successful exploitation may lead to the exposure of sensitive information, such as configuration files, environment settings, application assets, and log data, depending on the privileges of the compromised component. To mitigate this issue, Sage has implemented enhanced path validation and secure path resolution controls.

Affected Version(s)

Employee Self Service Q2 2026

References

CVSS V3.0

Score:
5.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Alexander Shepard – ashepard@paloaltonetworks.com
.