# Dayforce Payroll flaws allow SQLi, XSS, path traversal

Published: 2026-09-28 · Severity: routine · Sectors: technology
Canonical: https://vorant.io/reports/bd70c481-666b-5624-9d59-8a1ff8f3bb11/dayforce-payroll-flaws-allow-sqli-xss-path-traversal

> CERT Polska coordinated disclosure of three unauthenticated vulnerabilities in Dayforce Payroll R2026.2.0, including blind SQL injection and path traversal.

CERT Polska has disclosed three vulnerabilities in Dayforce Payroll software, confirmed in version R2026.2.0, after unsuccessful attempts to contact the vendor. The most severe, CVE-2026-73640, is an unauthenticated Time-Based Blind SQL Injection in the password recovery functionality, where a GET request parameter is interpreted as part of a SQL predicate, allowing an attacker to extract data via timing-based inference without needing credentials.

CVE-2026-73641 is a Reflected XSS affecting multiple endpoints, allowing an attacker to craft a malicious URL that executes arbitrary JavaScript in a victim's browser when opened — typically used for session hijacking or credential phishing against authenticated users. CVE-2026-73642 is an unauthenticated Path Traversal vulnerability in the file download functionality, where a file path parameter can be set to an absolute local path, potentially allowing retrieval of arbitrary files from the server.

Because the vendor did not respond to disclosure attempts, no patch is confirmed available at time of publication, and other Dayforce Payroll versions beyond R2026.2.0 may also be affected. Defenders running Dayforce Payroll should treat all three issues as unauthenticated, remotely exploitable web application flaws, monitor for anomalous GET requests targeting password recovery and file download endpoints, restrict external exposure of the application where possible, and watch for vendor patch releases given the lack of confirmed vendor engagement.

## Mentioned in this report

- Vulnerabilities: CVE-2026-73640, CVE-2026-73641, CVE-2026-73642

Source reporting: https://cert.pl/en/posts/2026/09/CVE-2026-73640

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/bd70c481-666b-5624-9d59-8a1ff8f3bb11/dayforce-payroll-flaws-allow-sqli-xss-path-traversal.
In the app the same report carries its extracted indicators, its detections with Splunk SPL and Microsoft KQL already written, live profiles of the actors and CVEs it names, and the vendor research on the same campaign. Slack alerts fire on the vendors, sectors and countries a reader follows. A new account starts with three days of all of it, no card: https://vorant.io/signup
