CyberRota Analysis
AI-GeneratedDayforce Payroll is vulnerable to a critical Path Traversal flaw in its file download functionality, allowing unauthenticated attackers to exploit the system by sending crafted GET requests to access arbitrary files on the server. This could lead to unauthorized exposure of sensitive data, posing significant risks to organizations using this software. All users of Dayforce Payroll, especially those running version R2026.2.0 or potentially affected versions, should prioritize immediate remediation efforts.
Original NVD Description
Dayforce Payroll is vulnerable to Path Traversal in file download functionality. An unauthenticated attacker can sent GET request with file path parameter set to any path including an absolute local file path. Because vendor contact attempts were unsuccessful, the vulnerability has only been confirmed in version R2026.2.0 but may also affect other versions.