A path traversal vulnerability exists in Sage Employee Self Serviceโs custom logo functionality due to improper validation of file path parameters. By leveraging directory traversal sequences and their encoded variants, an attacker may bypass directory restrictions and access files outside the application's intended file system scope. Successful exploitation would require knowledge of valid
Vulnerability
CVE-2026-67395
NVD
Refer to CVE-2026-67395 NVD advisory