Reflected XSS Vulnerability in Dayforce Payroll by Dayforce
CVE-2026-73641

5.1MEDIUM

Key Information:

Vendor

Dayforce

Status
Vendor
CVE Published:
28 September 2026

What is CVE-2026-73641?

The Dayforce Payroll product is susceptible to a reflected cross-site scripting (XSS) vulnerability that can be exploited through multiple endpoints. An attacker can craft a malicious URL which, when accessed, allows for the execution of arbitrary JavaScript code in the victim's browser. This vulnerability has been confirmed in version R2026.2.0, but there is potential for other versions to be affected as well. It is crucial for users to be aware of this issue and implement necessary precautions.

Affected Version(s)

Payroll R2026.2.0

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Dawid Dudek (4c1d8urn)
.