Impact
Dayforce Payroll’s file download feature suffers a path traversal flaw that can be exploited by unauthenticated users. By sending a crafted GET request with a file path parameter that contains an absolute path, an attacker can cause the server to return the contents of any file accessible to the application process, thus exposing sensitive data such as configuration files or credentials.
Affected Systems
The vulnerability has been confirmed in Dayforce Payroll version R2026.2.0; it may also impact other released versions that have not yet been evaluated. The issue resides specifically in the payroll product component as listed by the CNA.
Risk and Exploitability
With a CVSS base score of 9.2, the flaw is considered critical. The EPSS score is not available, but the high severity rating indicates a significant likelihood of exploitation. The vulnerability is not currently listed in CISA’s KEV catalog, implying that there is no confirmed public exploit yet, yet the attack vector is presumed to be remote and unauthenticated, making the risk substantial for any exposed systems.
OpenCVE Enrichment