SQL Injection Vulnerability in Dayforce Payroll by Ceridian
CVE-2026-73640

9.3CRITICAL

Key Information:

Vendor

Dayforce

Status
Vendor
CVE Published:
28 September 2026

What is CVE-2026-73640?

Dayforce Payroll, a product by Ceridian, is susceptible to a Time-Based Blind SQL Injection vulnerability within its password recovery functionality. This flaw allows unauthorized attackers to craft specially formed GET requests, injecting arbitrary SQL queries into the system. When processed, these queries can be executed, enabling the attackers to gain unauthorized access or extract sensitive data. While the vulnerability has been confirmed in version R2026.2.0, it is possible that other versions may also be affected due to the nature of the flaw.

Affected Version(s)

Payroll R2026.2.0

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Dawid Dudek (4c1d8urn)
.