VYPR

Sage Employee Self Service

by Sage

CVEs (1)

  • CVE-2026-67395MedSep 1, 2026
    risk 0.38cvss 5.9epss

    A path traversal vulnerability exists in Sage Employee Self Service’s custom logo functionality due to improper validation of file path parameters. By leveraging directory traversal sequences and their encoded variants, an attacker may bypass directory restrictions and access…