rootpwn

medium · CVSS v3 6.1 · CVSS v4 5.1

CVE-2026-73641

Dayforce Payroll is affected by a reflected XSS vulnerability that allows arbitrary JavaScript execution via crafted URLs. The flaw exists i

Overview

Dayforce Payroll is affected by a reflected XSS vulnerability that allows arbitrary JavaScript execution via crafted URLs. The flaw exists in version R2026.2.0 and may affect other releases. It can be exploited by attackers to steal session data or perform malicious actions in the victim's browser.

Description

Dayforce Payroll is vulnerable to Reflected XSS in multiple endpoints. An attacker can prepare a specially crafted URL that, when opened, results in arbitrary JavaScript execution in the victim's browser. Because vendor contact attempts were unsuccessful, the vulnerability has only been confirmed in version R2026.2.0 but may also affect other versions.

Impact

Confidentiality: attackers can steal sensitive payroll data by injecting scripts that capture form inputs. Integrity: malicious scripts could modify displayed data or submit fraudulent entries. Availability: not directly impacted. Defenders: end-users, administrators, and the payroll system.

Remediation

Apply the vendor's security patch for R2026.2.0 once released. Until then, restrict URL access to trusted users, enable input validation, and enforce a Content Security Policy (CSP) to block inline scripts. Disable or sanitize the affected endpoints if possible.

Risk context

The vulnerability is rated medium (CVSS 6.1) and currently has no EPSS score. While it does not pose an immediate widespread risk, attackers can exploit it via phishing or malicious links, so timely patching is advisable.

Affected products

  • Dayforce Payroll R2026.2.0
  • Dayforce Payroll
  • Dayforce Payroll R2026.1.0

Scores

Severity
medium
CVSS v2
4.3
CVSS v3
6.1
CVSS v4
5.1
EPSS
—

XSS Reflected XSS Dayforce Payroll Browser Exploit Medium Severity Input Validation

← All CVEs