---
id: CVE-2026-73642
title: "Dayforce Payroll is vulnerable to Path Traversal\_ in file download functionality"
summary: "Dayforce Payroll is vulnerable to Path Traversal\_ in file download functionality. An unauthenticated attacker can sent GET request with file path parameter set to any path including an\_absolute\nlocal file path.\n\n\nBecause vendor contact a…"
severity: critical
cvss: 9.2
cvssVector: 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N'
cwe:
  - CWE-22
vendor: Dayforce
product: Payroll
affected:
  - Payroll R2026.2.0
published: '2026-09-28'
updated: '2026-09-28'
sourceUpdated: '2026-09-28T16:31:16.073'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-73642'
references:
  - url: 'https://cert.pl/en/posts/2026/08/CVE-2026-73640'
    label: cvd@cert.pl
  - url: 'https://www.dayforce.com/how-we-help/dayforce/payroll-solutions'
    label: cvd@cert.pl
tags:
  - nvd
  - cve.org
cvssSource: cna
ingestedAt: '2026-09-28T14:12:02.173Z'
---

## Overview

Dayforce Payroll is vulnerable to Path Traversal  in file download functionality. An unauthenticated attacker can sent GET request with file path parameter set to any path including an absolute
local file path.


Because vendor contact attempts were unsuccessful, the vulnerability has only been confirmed in version R2026.2.0 but may also affect other versions.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
