🔐 CVE Alert

CVE-2026-73640

UNKNOWN 0.0

Time-based SQL Injection in Dayforce Payroll

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Dayforce Payroll is vulnerable to Time Based-Blind SQL Injection in password recovery functionality. The unauthenticated attacker can prepare GET request with one of the parameters filled in with an arbitrary SQL query. The parameter is interpreted as part of SQL predicate resulting in Time-Based Blind SQL Injection. Because vendor contact attempts were unsuccessful, the vulnerability has only been confirmed in version R2026.2.0 but may also affect other versions.

CWE CWE-89
Vendor dayforce
Product payroll
Published Sep 28, 2026
Stay Ahead of the Next One

Get instant alerts for dayforce payroll

Be the first to know when new unknown vulnerabilities affecting dayforce payroll are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

Dayforce / Payroll
R2026.2.0

References

NVD ↗ CVE.org ↗ EPSS Data ↗
cert.pl: https://cert.pl/en/posts/2026/09/CVE-2026-73640 dayforce.com: https://www.dayforce.com/how-we-help/dayforce/payroll-solutions

Credits

Dawid Dudek (4c1d8urn)