Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.2

CVE-2026-73642: Dayforce Payroll allows attackers to download any file

CVE-2026-73642 · published 4 days ago
Summary

The payroll system’s file‑download feature can be tricked into returning any file on the server, even system files. An attacker does not need to log in to exploit this, potentially exposing sensitive data or internal configurations. Apply the vendor’s patch or upgrade to a version where the issue is fixed, and restrict file‑download paths to only approved locations.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
dayforce payroll R2026.2.0
Original advisory text
Path Traversal in Dayforce Payroll
Dayforce Payroll is vulnerable to Path Traversal  in file download functionality. An unauthenticated attacker can sent GET request with file path parameter set to any path including an absolute
local file path.


Because vendor contact attempts were unsuccessful, the vulnerability has only been confirmed in version R2026.2.0 but may also affect other versions.
Fix within
Internet-facing 14 days
Internal 60 days
  • Not known to be exploited
  • Can be exploited automatically
  • Gives an attacker partial control
Severity
9.2 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-22Path Traversal
Timeline
Published28 Sep 2026
Updated2 Oct 2026
First seen28 Sep 2026
Sources
CVE-2026-73642 · MITRE
Track software like this
Free during beta