Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.3
CVE-2026-73640: Dayforce Payroll password reset may expose data
CVE-2026-73640 · published 12 days ago
Summary
The password‑recovery page in Dayforce Payroll can be manipulated to run hidden database commands, allowing an outsider to extract information. This works without needing to log in and may affect the current version and possibly earlier releases. Apply the vendor’s patch or disable the vulnerable recovery feature until it is fixed.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| dayforce | payroll | R2026.2.0 |
Original advisory text
Time-based SQL Injection in Dayforce Payroll
Dayforce Payroll is vulnerable to Time Based-Blind SQL Injection in password recovery functionality. The unauthenticated attacker can prepare GET request with one of the parameters filled in with an arbitrary SQL query. The parameter is interpreted as part of SQL predicate resulting in Time-Based Blind SQL Injection.
Because vendor contact attempts were unsuccessful, the vulnerability has only been confirmed in version R2026.2.0 but may also affect other versions.
Because vendor contact attempts were unsuccessful, the vulnerability has only been confirmed in version R2026.2.0 but may also affect other versions.
Internet-facing
3 days
Internal
60 days
- Not known to be exploited
- Can be exploited automatically
- Gives an attacker full control
Severity
9.3
Critical
Type
CWE-89SQL Injection
Timeline
Published28 Sep 2026
Updated7 Oct 2026
First seen28 Sep 2026
Track software like this
Free during beta