🔐 CVE Alert

CVE-2026-73642

UNKNOWN 0.0

Path Traversal in Dayforce Payroll

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Dayforce Payroll is vulnerable to Path Traversal  in file download functionality. An unauthenticated attacker can sent GET request with file path parameter set to any path including an absolute local file path. Because vendor contact attempts were unsuccessful, the vulnerability has only been confirmed in version R2026.2.0 but may also affect other versions.

CWE CWE-22
Vendor dayforce
Product payroll
Published Sep 28, 2026
Stay Ahead of the Next One

Get instant alerts for dayforce payroll

Be the first to know when new unknown vulnerabilities affecting dayforce payroll are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

Dayforce / Payroll
R2026.2.0

References

NVD ↗ CVE.org ↗ EPSS Data ↗
cert.pl: https://cert.pl/en/posts/2026/08/CVE-2026-73640 dayforce.com: https://www.dayforce.com/how-we-help/dayforce/payroll-solutions

Credits

Dawid Dudek (4c1d8urn)