Impact
Dayforce Payroll has a reflected cross‑site scripting flaw in several endpoints. An attacker can craft a malicious URL; when a victim opens it, arbitrary JavaScript runs in the victim’s browser. This allows the attacker to perform actions with the victim’s privileges, such as stealing credentials or injecting phishing content.
Affected Systems
The issue has been confirmed in Dayforce Payroll version R2026.2.0. The vendor’s contact attempts were unsuccessful, and it is unknown if other releases are affected, so any instance of Dayforce Payroll may be vulnerable until an official fix is released.
Risk and Exploitability
The CVSS score is 5.1, indicating moderate severity. EPSS data is unavailable, and the flaw is not listed in the CISA KEV catalog. The attack vector is client‑side, requiring a victim to click a crafted link; no additional privileges or network access are needed. While indirect, the ability to run arbitrary code in a user’s browser creates a significant risk for credential theft and session hijacking.
OpenCVE Enrichment