Description
Dayforce Payroll is vulnerable to Time Based-Blind SQL Injection in password recovery functionality. The unauthenticated attacker can prepare GET request with one of the parameters filled in with an arbitrary SQL query. The parameter is interpreted as part of SQL predicate resulting in Time-Based Blind SQL Injection.
Because vendor contact attempts were unsuccessful, the vulnerability has only been confirmed in version R2026.2.0 but may also affect other versions.
Published: 2026-09-28
Score: 9.3 Critical
EPSS: n/a
KEV: No
Impact: Data compromise via SQL injection
Action: Patch application
AI Analysis

Impact

Dayforce Payroll contains a time‑based blind SQL injection flaw in the password recovery feature. An unauthenticated attacker can craft a GET request where one of the parameters holds an arbitrary SQL statement that is incorporated into the database query predicate. The query’s execution time can then be measured, allowing the attacker to infer the truth value of injected conditions and gradually extract database contents or bypass authentication through blind inference. The vulnerability is a classic injection flaw identified as CWE‑89, and could enable an adversary to read or tamper with sensitive payroll information, thereby compromising data confidentiality and integrity.

Affected Systems

The flaw has been confirmed in Dayforce Payroll version R2026.2.0 and may also affect other versions, as no specific affected versions beyond R2026.2.0 have yet been documented. All installations that expose the password‑recovery endpoint without proper input validation are potentially susceptible, regardless of organizational size or geographic location.

Risk and Exploitability

The issue carries a CVSS score of 9.3, indicating critical severity, while the EPSS score is currently unavailable and the vulnerability is not listed in CISA’s KEV catalog. Attackers can exploit the flaw remotely by sending a crafted GET request to the password‑recovery endpoint, without needing prior authentication. Given the high severity rating and the straightforward nature of the exploit, systems that remain unpatched face a significant risk of data disclosure or manipulation, and automated scanners could trigger the attack surface without additional effort.

Generated by OpenCVE AI on September 28, 2026 at 15:33 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor‑supplied patch for Dayforce Payroll R2026.2.0 to eliminate the vulnerable code paths.
  • If a patch is not yet available, implement strict input validation or parameter sanitization for the password‑recovery endpoint to prevent arbitrary SQL execution.
  • Restrict external access to the password‑recovery endpoint by applying network segmentation or firewall rules, allowing only trusted internal IP ranges to reach it.
  • If both patch and input validation are unavailable, temporarily disable the password‑recovery functionality or enforce additional authentication such as multi‑factor authentication for the endpoint.

Generated by OpenCVE AI on September 28, 2026 at 15:33 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Dayforce
Dayforce payroll
Vendors & Products Dayforce
Dayforce payroll

Mon, 28 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Description Dayforce Payroll is vulnerable to Time Based-Blind SQL Injection in password recovery functionality. The unauthenticated attacker can prepare GET request with one of the parameters filled in with an arbitrary SQL query. The parameter is interpreted as part of SQL predicate resulting in Time-Based Blind SQL Injection. Because vendor contact attempts were unsuccessful, the vulnerability has only been confirmed in version R2026.2.0 but may also affect other versions.
Title Time-based SQL Injection in Dayforce Payroll
Weaknesses CWE-89
References
Metrics cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Dayforce Payroll
cve-icon MITRE

Status: PUBLISHED

Assigner: CERT-PL

Published:

Updated: 2026-09-28T13:12:34.751Z

Reserved: 2026-08-13T13:42:38.905Z

Link: CVE-2026-73640

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-09-28T14:17:16.843

Modified: 2026-09-28T16:31:16.073

Link: CVE-2026-73640

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-28T16:22:23Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')