External risk intelligence

Dayforce Payroll Path Traversal Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.2)

CVE-2026-73642

Dayforce is a payroll and human capital management platform typically deployed as a web-based service accessible to users over the internet, making its web-facing file download functionality a commonly reachable network service.

Path Traversal

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A vulnerability has been identified in the file download functionality of Dayforce Payroll, which could allow an unauthorized attacker to access sensitive files on the system. The issue stems from the system's inability to properly validate file paths when downloading files.

  • Attackers can access sensitive files.
  • Critical for confirming exposure in payroll systems.
  • Understand and communicate exposure to leadership.

Attack Path

How an attacker could exploit the issue

An attacker can exploit this vulnerability by sending a specially crafted GET request to the Dayforce Payroll system's file download feature. This request would include a malicious file path, allowing the attacker to access sensitive files on the server. The vulnerability could lead to unauthorized disclosure of sensitive information.

  • No authentication required to access.
  • Triggered by a GET request with a malicious path.
  • Risk of unauthorized local file access.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an unauthenticated attacker to access sensitive files on the Dayforce Payroll system when the file download functionality is used. The attacker could achieve this by sending a GET request that specifies an absolute local file path.

  • System files could be accessed.
  • Attacker sends crafted GET requests.
  • Unauthorized data disclosure may occur.

Operational Fix

Recommended remediation, mitigation, and detection steps

This critical vulnerability in Dayforce Payroll's file download functionality likely requires coordination between the platform or application owner and the security team. The first practical step is to identify all instances of the affected Dayforce Payroll system, confirm its external reachability and business criticality, and then determine the accountable owner for remediation planning. Given the vendor's unresponsiveness, a proactive approach to risk reduction and potential vendor management escalation may be necessary.

  • Platform or application owners should investigate.
  • Verify external reachability and business criticality.
  • Plan remediation with vendor coordination.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Dayforce Payroll?

Dayforce Payroll is a cloud-based human capital management platform used by organizations to automate payroll processing, benefits administration, and workforce management. It handles sensitive employee financial and personal data, serving as a centralized web portal that employees and administrators access to manage payroll workflows and generate related documentation.

What is the Path Traversal vulnerability in CVE-2026-73642?

Path Traversal, classified as CWE-22, occurs when software fails to properly filter file path inputs. In this vulnerability, the system allows a user to manipulate the file download function to request files outside of the intended directory. Because the application does not validate the requested path, an attacker can use special sequences to access arbitrary files on the server's local file system.

How can an attacker trigger this vulnerability?

An attacker triggers this flaw by sending a specially crafted HTTP GET request to the file download component of the application. The request includes a malicious parameter containing an absolute local file path instead of a standard filename. Importantly, this action does not require any authentication; however, the bug is specific to the file download functionality, meaning other parts of the application are not inherently triggered by the same request structure.

Is my organization at risk from CVE-2026-73642?

You are at higher risk if your instance is internet-facing, as Halo Surface Signal identifies Dayforce as a web-based service often deployed for external access. If your installation is publicly reachable, an attacker does not need prior network access or credentials to attempt this request. Organizations should evaluate whether their specific payroll deployment exposes this download functionality to the public internet.

What are the first steps to address this issue?

Begin by inventorying your systems to identify all instances of Dayforce Payroll within your environment. Verify which instances are accessible from the internet and confirm their business criticality with your internal teams. Since vendor communication is pending, focus on identifying the accountable owners for these systems so you can prepare for future remediation as updates become available.

References