Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.2
CVE-2026-73642: Dayforce Payroll allows attackers to download any file
CVE-2026-73642 · published 4 days ago
Summary
The payroll system’s file‑download feature can be tricked into returning any file on the server, even system files. An attacker does not need to log in to exploit this, potentially exposing sensitive data or internal configurations. Apply the vendor’s patch or upgrade to a version where the issue is fixed, and restrict file‑download paths to only approved locations.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| dayforce | payroll | R2026.2.0 |
Original advisory text
Path Traversal in Dayforce Payroll
Dayforce Payroll is vulnerable to Path Traversal in file download functionality. An unauthenticated attacker can sent GET request with file path parameter set to any path including an absolute
local file path.
Because vendor contact attempts were unsuccessful, the vulnerability has only been confirmed in version R2026.2.0 but may also affect other versions.
local file path.
Because vendor contact attempts were unsuccessful, the vulnerability has only been confirmed in version R2026.2.0 but may also affect other versions.
Internet-facing
14 days
Internal
60 days
- Not known to be exploited
- Can be exploited automatically
- Gives an attacker partial control
Severity
9.2
Critical
Type
CWE-22Path Traversal
Timeline
Published28 Sep 2026
Updated2 Oct 2026
First seen28 Sep 2026
Track software like this
Free during beta