CVE-2026-73642
Path Traversal in Dayforce Payroll
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Dayforce Payroll is vulnerable to Path Traversal in file download functionality. An unauthenticated attacker can sent GET request with file path parameter set to any path including an absolute local file path. Because vendor contact attempts were unsuccessful, the vulnerability has only been confirmed in version R2026.2.0 but may also affect other versions.
| CWE | CWE-22 |
| Vendor | dayforce |
| Product | payroll |
| Published | Sep 28, 2026 |
Stay Ahead of the Next One
Get instant alerts for dayforce payroll
Be the first to know when new unknown vulnerabilities affecting dayforce payroll are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
Affected Versions
Dayforce / Payroll
R2026.2.0
References
Credits
Dawid Dudek (4c1d8urn)