OCTOBER 6, 2026
Live Feed
Back to database
Case File

CVE-2026-73642

CRITICAL · CVSS 9.2 EPSS 0.42%

Source: NVD + CISA KEV + EPSS · Published 2026-09-28 · Last synced 2026-10-06

CyberRota Analysis

AI-Generated

Dayforce Payroll is vulnerable to a critical Path Traversal flaw in its file download functionality, allowing unauthenticated attackers to exploit the system by sending crafted GET requests to access arbitrary files on the server. This could lead to unauthorized exposure of sensitive data, posing significant risks to organizations using this software. All users of Dayforce Payroll, especially those running version R2026.2.0 or potentially affected versions, should prioritize immediate remediation efforts.

CVE
CVE-2026-73642
Severity
CRITICAL
CVSS
9.2
EPSS
0.42%

Original NVD Description

Dayforce Payroll is vulnerable to Path Traversal  in file download functionality. An unauthenticated attacker can sent GET request with file path parameter set to any path including an absolute local file path. Because vendor contact attempts were unsuccessful, the vulnerability has only been confirmed in version R2026.2.0 but may also affect other versions.