Workday
- Known vulnerabilities
- 0
- Still open
- 0
- KEV open
- 0
- Max CVSS (historical)
- —
Cumulative exposure
Low
Aggregates open CVEs (40%) + KEV (30%) + critical shared permissions (15%) + trackers (10%) + OS EOL (5%). Higher score = more exposed.
-
Open CVEs +0/+50
0 open CVEs, max CVSS 0.0, EPSS 0%
-
Active KEVs +0/+35
0 CISA KEVs still open
-
Permissions +0/+10
0 critical shared permission(s)
-
Trackers +0/+8
0 identification/profiling tracker(s)
-
EOL OS +0/+5
Installed OS is end-of-life
Based on permissions only: no CVE data referenced for this app.
Known vulnerabilities (CVE)
No CVE is currently referenced in NVD for this app on its platform.
The absence of CVEs is not a security guarantee — it can also mean nobody has audited or published findings.
Context
Context
Description
The Workday app provides secure, mobile access to your Workday applications on-the-go. As an employee, our simple interface allows you to • Review your pay, view or request time off, check in and out for work, submit your timesheet, and submit expenses quickly. • Get push notifications alerts and reminders for time tracking, important updates, and approvals. Immediately take action right from the app. • Browse your company directory, securely view coworker profiles, leave feedback, and take learning courses on-the-go. As a manager, you can take action wherever you are • Approve your employee requests easily. • View your team or individual profiles and immediately take actions relevant to your role, such as perform a job change, make a compensation change, or provide performance feedback. • Stay connected to your business by gaining quick insight into what's important through interactive reports and dashboards. And if your mobile device is ever lost or stolen, you can be confident that your data is secure. With support for Touch ID and Face ID, only you can access your information. Note: Your organization must authorize access to the Workday mobile app.
Data collected and shared
Source: App Store · App Privacy · 6 data item(s) declared
Indicative classification based on data sensitivity. "Shared" = transmitted to third parties (publisher-declared).
FAQ
FAQ: Workday
Why are no CVEs listed for Workday?
No CVE is currently referenced in NVD for Workday (com.workday.workdayapp) with a iOS CPE configuration. Either none has been publicly disclosed, or none has been mapped yet. Absence of a CVE is not a security guarantee.
What is the latest known version of Workday?
The most recent version of Workday (com.workday.workdayapp) tracked by Appaloosa Scout is 2026.08.0, published by Workday, Inc.