CVE-2026-73642
Received Received - Intake

Path Traversal in Dayforce Payroll File Download

Vulnerability report for CVE-2026-73642, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-28

Last updated on: 2026-09-28

Assigner: CERT.PL

Description

Dayforce Payroll is vulnerable to Path Traversal  in file download functionality. An unauthenticated attacker can sent GET request with file path parameter set to any path including an absolute local file path. Because vendor contact attempts were unsuccessful, the vulnerability has only been confirmed in version R2026.2.0 but may also affect other versions.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-28
Last Modified
2026-09-28
Generated
2026-09-28
AI Q&A
2026-09-28
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
dayforce payroll r2026.2.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-22 The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Dayforce Payroll has a Path Traversal vulnerability in its file download feature. An unauthenticated attacker can send a specially crafted GET request with a file path parameter set to an absolute local file path, potentially accessing unauthorized files on the server.

Detection Guidance

Detect this vulnerability by checking for unusual file download requests in web server logs. Look for GET requests with file path parameters containing absolute local paths like /etc/passwd or C:\Windows\win.ini. Monitor for unauthorized access attempts to sensitive files.

Impact Analysis

This vulnerability allows attackers to read sensitive files on the server, which could include configuration files, user data, or other confidential information. It may lead to data breaches, unauthorized access, or further exploitation of the system.

Compliance Impact

This vulnerability can lead to non-compliance with GDPR, HIPAA, and other regulations by exposing sensitive personal or health data. Organizations may face legal penalties, fines, or reputational damage due to data breaches resulting from this issue.

Mitigation Strategies

Immediately update Dayforce Payroll to the latest version beyond R2026.2.0. Restrict file download functionality to authenticated users only. Implement input validation to block absolute path traversal attempts in file path parameters.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-73642. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart