CVE-2026-73641: Multiple Reflected XSS in Dayforce Payroll
Dayforce Payroll is vulnerable to Reflected XSS in multiple endpoints. An attacker can prepare a specially crafted URL that, when opened, results in arbitrary JavaScript execution in the victim's browser.
Because vendor contact attempts were unsuccessful, the vulnerability has only been confirmed in version R2026.2.0 but may also affect other versions.
Affected Software
Event History
Frequently Asked Questions
What does an attacker need to exploit this issue?
The attacker needs to craft a malicious URL and induce a victim to open it. Successful exploitation executes arbitrary JavaScript in the victim's browser.
Which versions are known to be affected?
The issue has been confirmed only in Dayforce Payroll version R2026.2.0. Other versions may also be affected, but this has not been confirmed.
Is a vendor fix or mitigation available?
The available information does not identify a vendor fix or workaround. Vendor contact attempts were unsuccessful.