Impact
Dayforce Payroll contains a time‑based blind SQL injection flaw in the password recovery feature. An unauthenticated attacker can craft a GET request where one of the parameters holds an arbitrary SQL statement that is incorporated into the database query predicate. The query’s execution time can then be measured, allowing the attacker to infer the truth value of injected conditions and gradually extract database contents or bypass authentication through blind inference. The vulnerability is a classic injection flaw identified as CWE‑89, and could enable an adversary to read or tamper with sensitive payroll information, thereby compromising data confidentiality and integrity.
Affected Systems
The flaw has been confirmed in Dayforce Payroll version R2026.2.0 and may also affect other versions, as no specific affected versions beyond R2026.2.0 have yet been documented. All installations that expose the password‑recovery endpoint without proper input validation are potentially susceptible, regardless of organizational size or geographic location.
Risk and Exploitability
The issue carries a CVSS score of 9.3, indicating critical severity, while the EPSS score is currently unavailable and the vulnerability is not listed in CISA’s KEV catalog. Attackers can exploit the flaw remotely by sending a crafted GET request to the password‑recovery endpoint, without needing prior authentication. Given the high severity rating and the straightforward nature of the exploit, systems that remain unpatched face a significant risk of data disclosure or manipulation, and automated scanners could trigger the attack surface without additional effort.
OpenCVE Enrichment