CRITICAL 9.2 NVD
CVE-2026-73642
Dayforce Payroll is vulnerable to Path Traversal in file download functionality. An unauthenticated attacker can sent GET request with file path parameter set
Dayforce Payroll is vulnerable to Path Traversal in file download functionality. An unauthenticated attacker can sent GET request with file path parameter set to any path including an absolute
local file path.
Because vendor contact attempts were unsuccessful, the vulnerability has only been confirmed in version R2026.2.0 but may also affect other versions.
References
- https://cert.pl/en/posts/2026/08/CVE-2026-73640
- https://www.dayforce.com/how-we-help/dayforce/payroll-solutions
This critical severity vulnerability with a CVSS score of 9.2 was published on 2026-09-28 via NVD.
Risk Timeline
CVE Disclosed2026-09-28 · -1 days ago
Remediation Resources
Official Advisory
cert.pl/en/posts/2026/08/CVE-2026-73640Analysis & PoC
www.dayforce.com/how-we-help/dayforce/payroll-solutions
vulnfeed aggregates 13625 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.