External risk intelligence

Dayforce Payroll Blind SQL Injection in Password Recovery

CVE advisorySeverity: CRITICAL (CVSS 9.3)

CVE-2026-73640

The vulnerability exists in a password recovery function, which is a standard, unauthenticated, public-facing web component designed to be accessible to users over the internet. Because it provides a critical entry point for identity management on a web application, it is exposed by design in normal deployments.

SQL Injection

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory highlights a critical vulnerability in Dayforce Payroll's password recovery feature, which could allow an unauthenticated attacker to execute malicious SQL commands by manipulating specific request parameters. This SQL injection could potentially lead to unauthorized access or manipulation of sensitive data.

  • A password reset flaw allows unauthenticated attackers to inject commands.
  • This impacts user identity and data integrity at a fundamental level.
  • Confirm if your organization uses this system and assess exposure.

Attack Path

How an attacker could exploit the issue

An attacker can exploit this vulnerability by sending crafted GET requests to the password recovery functionality of Dayforce Payroll. Since no authentication is required, an attacker can intercept or construct these requests, injecting arbitrary SQL commands into a parameter. This allows them to manipulate the database queries, potentially leading to unauthorized access or data compromise.

  • No authentication needed to attack.
  • Time-based blind SQL injection trigger.
  • Potential for unauthorized access.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability in Dayforce Payroll's password recovery could allow an unauthenticated attacker to infer sensitive information through time-based blind SQL injection. This could occur when an attacker crafts a GET request with a malicious SQL query in specific parameters, potentially impacting the system's ability to securely manage user credentials.

  • Affects password recovery functionality.
  • Malicious GET requests could exploit parameters.
  • System data exposure is a potential consequence.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability in Dayforce Payroll's password recovery function requires immediate attention from application owners and security teams to identify and secure affected instances. The first step is to locate all deployments of the affected technology, determine their exposure and business criticality, and then assign ownership for remediation.

  • Application owners must prioritize this.
  • Verify external accessibility and criticality.
  • Plan remediation based on exposure.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Dayforce Payroll?

Dayforce Payroll is a comprehensive human capital management platform designed to automate payroll processing, tax compliance, and workforce management tasks. Organizations use this enterprise software to handle sensitive employee financial data, manage time and attendance, and facilitate secure user access through built-in identity features like password recovery.

What does CVE-2026-73640 mean?

This identifier refers to a Time-Based Blind SQL Injection vulnerability, classified as CWE-89. It means the software does not properly sanitize input in its password recovery feature. An attacker can send specially crafted data to the database; because it is 'blind,' the attacker observes how long the server takes to respond to infer hidden information, effectively 'asking' the database questions it shouldn't answer.

How can an attacker trigger this vulnerability?

An attacker triggers this flaw by sending a specifically crafted GET request to the password recovery function. Because the input parameter is processed directly as part of a database command, the system executes the unintended SQL instructions. Importantly, this does not require a legitimate user account or any prior authentication to initiate.

Is my instance of Dayforce Payroll at risk?

According to Halo Surface Signal, this vulnerability exists in a standard, public-facing web component designed to be reachable over the internet. Because password recovery functions must be accessible for users to regain account access, any internet-facing deployment is considered exposed by design, making it a higher priority for review than internal-only components.

What should I do to address this issue?

Begin by auditing your environment to identify all active instances of the software. Once located, assess the business criticality and network exposure of each deployment. Coordinate with your application owners to monitor the system for unusual traffic patterns related to password reset activity while awaiting official vendor guidance or security updates.

References