CVE-2026-67395
Last modified
CVE-2026-67395 is a medium-severity vulnerability rated 5.9/10 on the CVSS scale. A path traversal vulnerability exists in Sage Employee Self Service’s custom logo functionality due to improper validation of file path parameters. By leveraging directory traversal sequences and their encoded variants, an attacker may bypass directory restrictions and access files outside the application's intended file system scope. EPSS estimates a 0.84% chance of exploitation in the next 30 days.
Description
A path traversal vulnerability exists in Sage Employee Self Service’s custom logo functionality due to improper validation of file path parameters. By leveraging directory traversal sequences and their encoded variants, an attacker may bypass directory restrictions and access files outside the application's intended file system scope. Successful exploitation would require knowledge of valid file names and paths. Depending on the privileges of the affected component, exploitation could result in the disclosure of sensitive information, including configuration files, environment settings, application assets, and log data. The vulnerability has been remediated through enhanced path validation and secure path resolution controls that prevent access to unauthorised locations.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Sage | Employee Self Service | >= Q2 2026, < Q2 2026 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-67395?
How severe is CVE-2026-67395?
How do I fix CVE-2026-67395?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-67388Heap-based buffer overflow in SQL Server allows an authorize…8.8
- CVE-2026-67389Out-of-bounds read in SQL Server allows an authorized attack…6.5
- CVE-2026-6739Mattermost versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, 10.1…7.2
- CVE-2026-67390Buffer over-read in SQL Server allows an authorized attacker…6.5
- CVE-2026-67393Buffer over-read in SQL Server allows an authorized attacker…6.5
- CVE-2026-67394A critical local privilege escalation via OS command injecti…9
- CVE-2026-67397Path traversal in Plesk 18.0.79.9 and earlier and 18.0.80 th…8.5
- CVE-2026-67398Missing authorization vulnerability has been discovered in 2…8.2
- CVE-2026-67399Deserialization of untrusted data in WHMCS 9.0.0 before 9.0.…9.3
- CVE-2026-6740The Nexter Blocks – Gutenberg Blocks, Page Builder & AI Webs…6.4
- CVE-2026-67401A vulnerability in cPanel allows a mail-enabled account to a…9.9
- CVE-2026-67402An insecure Apache configuration in ConfigServer Security & …9.2
Are you affected by CVE-2026-67395?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
