CVE-2026-67395
Received Received - Intake

Path Traversal in Sage Employee Self Service

Vulnerability report for CVE-2026-67395, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-01

Last updated on: 2026-09-01

Assigner: HackerOne

Description

A path traversal vulnerability exists in Sage Employee Self Service’s custom logo functionality due to improper validation of file path parameters. By leveraging directory traversal sequences and their encoded variants, an attacker may bypass directory restrictions and access files outside the application's intended file system scope. Successful exploitation would require knowledge of valid file names and paths. Depending on the privileges of the affected component, exploitation could result in the disclosure of sensitive information, including configuration files, environment settings, application assets, and log data. The vulnerability has been remediated through enhanced path validation and secure path resolution controls that prevent access to unauthorised locations.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-01
Last Modified
2026-09-01
Generated
2026-09-01
AI Q&A
2026-09-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
sage sage_employee_self_service *
sage sagehrms From Q4_SR2026 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-22 The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a path traversal vulnerability in Sage Employee Self Service’s custom logo feature. It occurs because the application does not properly validate file path parameters, allowing attackers to use directory traversal sequences (like ../) or their encoded forms to bypass restrictions and access files outside the intended scope. Exploitation requires knowledge of valid file paths and could lead to unauthorized access to sensitive files such as configuration files, environment settings, application assets, or logs.

Impact Analysis

If exploited, this vulnerability could allow attackers to access sensitive information stored on the server, including configuration files, environment settings, application assets, and log data. The impact depends on the privileges of the affected component. While the vulnerability does not allow direct code execution or modification of data, unauthorized access to sensitive files could lead to data breaches, compliance violations, or further attacks within the system.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, which may result in violations of compliance standards such as GDPR or HIPAA. Unauthorized access to personal or health-related data could lead to legal penalties, reputational damage, and loss of trust. Organizations must ensure proper remediation to maintain compliance with data protection regulations.

Mitigation Strategies

Apply the latest SageHRMS Q2 2026 update or later, which includes enhanced path validation and secure path resolution controls to prevent unauthorized file access. Ensure your system is upgraded to Q4 SR2026 or later as required by the release notes.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-67395. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart