medium · CVSS v3 6.1 · CVSS v4 5.1
CVE-2026-73641
Dayforce Payroll is affected by a reflected XSS vulnerability that allows arbitrary JavaScript execution via crafted URLs. The flaw exists i
Overview
Dayforce Payroll is affected by a reflected XSS vulnerability that allows arbitrary JavaScript execution via crafted URLs. The flaw exists in version R2026.2.0 and may affect other releases. It can be exploited by attackers to steal session data or perform malicious actions in the victim's browser.
Description
Dayforce Payroll is vulnerable to Reflected XSS in multiple endpoints. An attacker can prepare a specially crafted URL that, when opened, results in arbitrary JavaScript execution in the victim's browser. Because vendor contact attempts were unsuccessful, the vulnerability has only been confirmed in version R2026.2.0 but may also affect other versions.
Impact
Confidentiality: attackers can steal sensitive payroll data by injecting scripts that capture form inputs. Integrity: malicious scripts could modify displayed data or submit fraudulent entries. Availability: not directly impacted. Defenders: end-users, administrators, and the payroll system.
Remediation
Apply the vendor's security patch for R2026.2.0 once released. Until then, restrict URL access to trusted users, enable input validation, and enforce a Content Security Policy (CSP) to block inline scripts. Disable or sanitize the affected endpoints if possible.
Risk context
The vulnerability is rated medium (CVSS 6.1) and currently has no EPSS score. While it does not pose an immediate widespread risk, attackers can exploit it via phishing or malicious links, so timely patching is advisable.
Affected products
- Dayforce Payroll R2026.2.0
- Dayforce Payroll
- Dayforce Payroll R2026.1.0
Scores
- Severity
- medium
- CVSS v2
- 4.3
- CVSS v3
- 6.1
- CVSS v4
- 5.1
- EPSS
- —