Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.3

CVE-2026-73640: Dayforce Payroll password reset may expose data

CVE-2026-73640 · published 12 days ago
Summary

The password‑recovery page in Dayforce Payroll can be manipulated to run hidden database commands, allowing an outsider to extract information. This works without needing to log in and may affect the current version and possibly earlier releases. Apply the vendor’s patch or disable the vulnerable recovery feature until it is fixed.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
dayforce payroll R2026.2.0
Original advisory text
Time-based SQL Injection in Dayforce Payroll
Dayforce Payroll is vulnerable to Time Based-Blind SQL Injection in password recovery functionality. The unauthenticated attacker can prepare GET request with one of the parameters filled in with an arbitrary SQL query. The parameter is interpreted as part of SQL predicate resulting in Time-Based Blind SQL Injection.
Because vendor contact attempts were unsuccessful, the vulnerability has only been confirmed in version R2026.2.0 but may also affect other versions.
Fix within
Internet-facing 3 days
Internal 60 days
  • Not known to be exploited
  • Can be exploited automatically
  • Gives an attacker full control
Severity
9.3 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-89SQL Injection
Timeline
Published28 Sep 2026
Updated7 Oct 2026
First seen28 Sep 2026
Sources
CVE-2026-73640 · MITRE
Track software like this
Free during beta