Description
Dayforce Payroll is vulnerable to Path Traversal  in file download functionality. An unauthenticated attacker can sent GET request with file path parameter set to any path including an absolute
local file path.


Because vendor contact attempts were unsuccessful, the vulnerability has only been confirmed in version R2026.2.0 but may also affect other versions.
Published: 2026-09-28
Score: 9.2 Critical
EPSS: n/a
KEV: No
Impact: Remote file disclosure, allowing attackers to read arbitrary system files
Action: Immediate Mitigation
AI Analysis

Impact

Dayforce Payroll’s file download feature suffers a path traversal flaw that can be exploited by unauthenticated users. By sending a crafted GET request with a file path parameter that contains an absolute path, an attacker can cause the server to return the contents of any file accessible to the application process, thus exposing sensitive data such as configuration files or credentials.

Affected Systems

The vulnerability has been confirmed in Dayforce Payroll version R2026.2.0; it may also impact other released versions that have not yet been evaluated. The issue resides specifically in the payroll product component as listed by the CNA.

Risk and Exploitability

With a CVSS base score of 9.2, the flaw is considered critical. The EPSS score is not available, but the high severity rating indicates a significant likelihood of exploitation. The vulnerability is not currently listed in CISA’s KEV catalog, implying that there is no confirmed public exploit yet, yet the attack vector is presumed to be remote and unauthenticated, making the risk substantial for any exposed systems.

Generated by OpenCVE AI on September 28, 2026 at 15:32 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Dayforce Payroll system to the latest version once the vendor releases a patch that addresses the path traversal issue.
  • Restrict the file download API to authenticated users and limit served paths to a dedicated safe directory, rejecting any requests that attempt directory traversal.
  • Configure the web application firewall or equivalent network security controls to detect and block URLs containing traversal sequences such as ".." or absolute path references, and monitor logs for anomalous download attempts.

Generated by OpenCVE AI on September 28, 2026 at 15:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Dayforce
Dayforce payroll
Vendors & Products Dayforce
Dayforce payroll

Mon, 28 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Description Dayforce Payroll is vulnerable to Path Traversal  in file download functionality. An unauthenticated attacker can sent GET request with file path parameter set to any path including an absolute local file path. Because vendor contact attempts were unsuccessful, the vulnerability has only been confirmed in version R2026.2.0 but may also affect other versions.
Title Path Traversal in Dayforce Payroll
Weaknesses CWE-22
References
Metrics cvssV4_0

{'score': 9.2, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N'}


Subscriptions

Dayforce Payroll
cve-icon MITRE

Status: PUBLISHED

Assigner: CERT-PL

Published:

Updated: 2026-09-28T13:12:46.426Z

Reserved: 2026-08-13T13:42:38.905Z

Link: CVE-2026-73642

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-09-28T14:17:17.160

Modified: 2026-09-28T16:31:16.073

Link: CVE-2026-73642

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-28T16:22:16Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')