Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-73640— Time-based SQL Injection in Dayforce Payroll

Quick assessment

Affected
Dayforce Payroll
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Dayforce 薪酬系统存在基于时间的盲注 SQL 注入(Time-Based Blind SQL Injection)漏洞,该漏洞存在于密码恢复功能中。未认证的 attackers 可以构造一个 GET 请求,并在其中一个参数中填充任意的 SQL 查询语句。由于该参数被当作 SQL 谓词(predicate)的一部分进行解析,从而导致发生基于时间的盲注 SQL 注入攻击。 由于未能成功联系到供应商,该漏洞目前仅在 R2026.2.0 版本中确认存在,但其他版本也可能受到影响。

CVSS 9.3 · Critical

Possible ATT&CK Techniques 1 AI

T1190 · Exploit Public-Facing Application
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-73640

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Time-based SQL Injection in Dayforce Payroll
Source: CVE Program / CVE List V5
Vulnerability Description
Dayforce Payroll is vulnerable to Time Based-Blind SQL Injection in password recovery functionality. The unauthenticated attacker can prepare GET request with one of the parameters filled in with an arbitrary SQL query. The parameter is interpreted as part of SQL predicate resulting in Time-Based Blind SQL Injection. Because vendor contact attempts were unsuccessful, the vulnerability has only been confirmed in version R2026.2.0 but may also affect other versions.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
SQL命令中使用的特殊元素转义处理不恰当(SQL注入)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Dayforce Payroll R2026.2.0 -

II. Public POCs for CVE-2026-73640

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-73640

请登录查看更多情报信息。

Other References for CVE-2026-73640 (2)

Same Patch Batch · Dayforce · 2026-09-28 · 3 CVEs total

CVE-2026-73642 9.2 CRITICAL Path Traversal in Dayforce Payroll
CVE-2026-73641 5.1 MEDIUM Multiple Reflected XSS in Dayforce Payroll

IV. Related Vulnerabilities

V. Comments for CVE-2026-73640

No comments yet


Leave a comment