CVE-2026-73640
Received Received - Intake

Time-Based Blind SQL Injection in Dayforce Payroll

Vulnerability report for CVE-2026-73640, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-28

Last updated on: 2026-09-28

Assigner: CERT.PL

Description

Dayforce Payroll is vulnerable to Time Based-Blind SQL Injection in password recovery functionality. The unauthenticated attacker can prepare GET request with one of the parameters filled in with an arbitrary SQL query. The parameter is interpreted as part of SQL predicate resulting in Time-Based Blind SQL Injection. Because vendor contact attempts were unsuccessful, the vulnerability has only been confirmed in versionΒ R2026.2.0 but may also affect other versions.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-28
Last Modified
2026-09-28
Generated
2026-09-28
AI Q&A
2026-09-28
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
dayforce payroll From R2026.2.0 (exc)
dayforce payroll r2026.2.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-89 The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Dayforce Payroll has a Time-Based Blind SQL Injection vulnerability in its password recovery feature. An unauthenticated attacker can craft a GET request with a malicious SQL query in a parameter. This parameter is processed as part of a SQL predicate, allowing the attacker to manipulate the database indirectly without direct access.

Detection Guidance

To detect Time-Based Blind SQL Injection in Dayforce Payroll's password recovery functionality, monitor HTTP GET requests to the affected endpoint. Look for unusual parameters containing SQL-like syntax such as 'OR 1=1-- or WAITFOR DELAY commands. Use tools like Burp Suite or OWASP ZAP to intercept and analyze requests.

Impact Analysis

This vulnerability allows attackers to extract sensitive data from the database, such as user credentials or payroll information, by exploiting the SQL injection. It could also enable unauthorized modifications to the database, leading to data corruption or loss. Since it is unauthenticated, any user interacting with the vulnerable system is at risk.

Compliance Impact

This vulnerability can lead to unauthorized access to sensitive personal data, violating GDPR's data protection requirements and HIPAA's safeguards for protected health information. Organizations using the affected software may face compliance breaches, legal penalties, and reputational damage due to potential data exposure.

Mitigation Strategies

Immediately disable the password recovery functionality if possible. Apply input validation to sanitize all GET request parameters. Update to a patched version once available. Monitor network traffic for suspicious SQL-like patterns in requests to the affected endpoint.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-73640. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart