CVE-2026-67395: Path Traversal

Published Sep 1, 2026
·
Updated

A path traversal vulnerability exists in Sage Employee Self Service’s custom logo functionality due to improper validation of file path parameters. By leveraging directory traversal sequences and their encoded variants, an attacker may bypass directory restrictions and access files outside the application's intended file system scope. Successful exploitation would require knowledge of valid file names and paths. Depending on the privileges of the affected component, exploitation could result in the disclosure of sensitive information, including configuration files, environment settings, application assets, and log data. The vulnerability has been remediated through enhanced path validation and secure path resolution controls that prevent access to unauthorised locations.

Event History

Sep 1, 2026
CVE Published
via MITRE·02:07 AM
Data Sourced
via MITRE·02:07 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

What does an attacker need to exploit this issue?

An attacker can attempt exploitation remotely without authentication or user interaction, but must know valid file names and paths. Exploitation also depends on successfully using directory-traversal sequences or encoded variants against the custom logo functionality.

2

What information could be exposed if exploitation succeeds?

The issue may allow reading files outside the intended application file-system scope, subject to the affected component's privileges. Potentially exposed data includes configuration files, environment settings, application assets, and logs.

3

What remediation is described?

The vulnerability was remediated by enhanced path validation and secure path-resolution controls designed to prevent access to unauthorized locations.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203