Dayforce Payroll flaws go public after vendor stays silent

Published

Poland's national computer emergency response team has gone public with three vulnerabilities in Dayforce Payroll after it could not get a response from the vendor. Two of the three can be reached by an attacker who has not logged in, in software whose whole job is to hold salary and personal data.

CERT Polska's advisory, published on September 28, 2026, credits researcher Dawid Dudek (4c1d8urn) with the report. CERT Polska coordinated the disclosure, and says that because its attempts to contact the vendor were unsuccessful, the flaws have only been confirmed in version R2026.2.0, though they may affect other versions too.

Three bugs, two of them open to anyone

CERT Polska has not published CVSS scores for any of the three, so they are listed here in the order the advisory gives them:

The advisory does not say whether any of the flaws have been exploited, and IntelFusions has seen no report that they have. It also does not describe what data could be reached through them, and the full technical detail sits with CERT Polska's advisory.

Why a silent vendor makes this worse

Coordinated disclosure normally ends with a patch and an advisory landing on the same day. Here the process ended with publication and nothing from the vendor, which leaves customers with details of the bugs but no fixed version to install. Payroll systems are a high-value target: they concentrate bank details, national identifiers and compensation data for an entire workforce, and a password-recovery page is by design reachable from outside.

CERT Polska has become one of the most consistent public channels for this kind of disclosure. IntelFusions has previously covered its reports on flaws such as a KAON router bug that leaked the admin password. More on the Polish CERT's role is on our Poland profile.

No patch yet, so contact Dayforce and limit exposure

With no vendor fix announced, organizations running Dayforce Payroll should ask Dayforce directly whether their deployment is affected and when a fix will ship. In the meantime, where the deployment allows it, restrict access to the application to known networks or behind a VPN, place a web application firewall with SQL injection and path traversal rules in front of it, and review web and database logs for unusual requests to the password recovery and file download functions.

A disclosure that ends without the vendor in the room is a warning about more than three bugs. It tells customers something about how the next report will be handled too.

This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.

Read the full analysis on IntelFusions