Full Report
CERT Polska has received a report about 3 vulnerabilities (from CVE-2026-73640 to CVE-2026-73642) found in Dayforce Payroll software.
Analysis Summary
# Vulnerability: Multiple Flaws in Dayforce Payroll (SQLi, XSS, Path Traversal)
## CVE Details
- **CVE ID:** CVE-2026-73640, CVE-2026-73641, CVE-2026-73642
- **CVSS Score:** Not explicitly provided in the report (Estimated High/Critical based on descriptions)
- **CWE:**
- CWE-89: SQL Injection (CVE-2026-73640)
- CWE-79: Cross-site Scripting (CVE-2026-73641)
- CWE-22: Path Traversal (CVE-2026-73642)
## Affected Systems
- **Products:** Dayforce Payroll
- **Versions:** R2026.2.0 (Confirmed); other versions may also be affected.
- **Configurations:** Default installations using password recovery and file download functionalities.
## Vulnerability Description
Three distinct vulnerabilities were identified in the Dayforce Payroll software:
1. **CVE-2026-73640 (SQL Injection):** A Time-Based Blind SQL Injection exists within the password recovery functionality. The application fails to properly neutralize special elements in GET request parameters, allowing an unauthenticated attacker to execute arbitrary SQL queries by observing time delays in server responses.
2. **CVE-2026-73641 (Reflected XSS):** Multiple endpoints fail to sanitize user input before reflecting it into web pages. An attacker can craft a malicious URL that executes arbitrary JavaScript in the context of the victim's browser session.
3. **CVE-2026-73642 (Path Traversal):** The file download functionality does not sufficiently restrict file path parameters. An unauthenticated attacker can use GET requests with manipulated path parameters (including absolute local paths) to access unauthorized files on the server.
## Exploitation
- **Status:** Reported via CVD; no evidence of exploitation in the wild provided. No public PoC currently linked, though technical vectors are described.
- **Complexity:**
- CVE-2026-73640: Medium (Time-based extraction is slower)
- CVE-2026-73641/42: Low
- **Attack Vector:** Network (Remote/Unauthenticated)
## Impact
- **Confidentiality:** High (Ability to extract database contents and local server files)
- **Integrity:** Medium to High (XSS can lead to session hijacking; SQLi may allow data modification depending on DB permissions)
- **Availability:** Low to Medium (Blind SQLi can cause database resource exhaustion)
## Remediation
### Patches
- **Status:** As of the report date, vendor contact attempts by CERT Polska were **unsuccessful**. No official patches for version R2026.2.0 have been confirmed.
### Workarounds
- **Network Filtering:** Restrict access to the Dayforce Payroll web interface to trusted IP ranges or via VPN.
- **WAF Rules:** Implement Web Application Firewall (WAF) signatures to detect and block:
- Common SQL injection patterns (e.g., `SLEEP()`, `WAITFOR DELAY`).
- Path traversal sequences (e.g., `../`, `..\`, or absolute paths like `/etc/passwd` or `C:\`).
- Script tags or event handlers in GET parameters.
## Detection
- **Indicators of Compromise:**
- Web server logs showing unusual `GET` parameters in the password recovery and file download endpoints.
- Repeated requests to the same URL with incremental time delays.
- Access logs showing requests for system files or configuration files via the payroll application.
- **Detection methods:** Audit web server access logs for strings such as `..%2f`, `..%5c`, and SQL syntax in URL parameters.
## References
- **CERT Polska Advisory:** hxxps[://]cert[.]pl/en/posts/2026/09/vulnerabilities-in-dayforce-payroll-software/
- **CVD Policy:** hxxps[://]cert[.]pl/en/cvd/
- **CVE Database:**
- hxxps[://]www[.]cve[.]org/CVERecord?id=CVE-2026-73640
- hxxps[://]www[.]cve[.]org/CVERecord?id=CVE-2026-73641
- hxxps[://]www[.]cve[.]org/CVERecord?id=CVE-2026-73642