Junglewise Threat Intelligence

CVE-2026-67395: Sage Employee Self Service path traversal in logo functionality

CVE-2026-67395 · Severity: medium · CVSS 5.9 · Published 2026-09-01

Executive brief

Sage Employee Self Service allows users to upload custom logos through a web interface. A flaw in the file path validation allows an attacker to use directory traversal techniques to read sensitive files outside the intended application directory, such as configuration files and logs. Exploitation could expose confidential business data and system details.

Technical details

A path traversal vulnerability exists in the custom logo upload functionality of Sage Employee Self Service due to insufficient validation of file path parameters. An attacker can craft requests using directory traversal sequences (e.g., "../") and their URL-encoded variants to bypass directory restrictions and access arbitrary files on the system. No authentication bypass is required beyond normal access to the logo upload feature; the attacker must have knowledge of valid file paths to successfully exploit this. Successful exploitation results in information disclosure, including configuration files, environment settings, and application logs. The vendor has released a patch implementing enhanced path validation and secure path resolution controls.

Affected products

  • Sage Employee Self Service <UNKNOWN>

Timeline

  • 2026-09-01: disclosed

References