Path Traversal Vulnerability in Dayforce Payroll by Dayforce
CVE-2026-73642

9.2CRITICAL

Key Information:

Vendor

Dayforce

Status
Vendor
CVE Published:
28 September 2026

What is CVE-2026-73642?

Dayforce Payroll has a vulnerability in its file download functionality, allowing an unauthenticated attacker to manipulate file path parameters. By sending a GET request with a crafted file path, the attacker can exploit the system to access unauthorized files on the server, potentially exposing sensitive information. This issue has been confirmed in version R2026.2.0 but may impact other versions as well.

Affected Version(s)

Payroll R2026.2.0

References

CVSS V4

Score:
9.2
Severity:
CRITICAL
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Dawid Dudek (4c1d8urn)
.