CVE-2026-73640
Time-based SQL Injection in Dayforce Payroll
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Dayforce Payroll is vulnerable to Time Based-Blind SQL Injection in password recovery functionality. The unauthenticated attacker can prepare GET request with one of the parameters filled in with an arbitrary SQL query. The parameter is interpreted as part of SQL predicate resulting in Time-Based Blind SQL Injection. Because vendor contact attempts were unsuccessful, the vulnerability has only been confirmed in version R2026.2.0 but may also affect other versions.
| CWE | CWE-89 |
| Vendor | dayforce |
| Product | payroll |
| Published | Sep 28, 2026 |
Stay Ahead of the Next One
Get instant alerts for dayforce payroll
Be the first to know when new unknown vulnerabilities affecting dayforce payroll are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
Affected Versions
Dayforce / Payroll
R2026.2.0
References
Credits
Dawid Dudek (4c1d8urn)