CVE-2026-54782
CRITICALCoreWCF: Authentication bypass in CoreWCF SAML 1.1 / 2.0 token signature validation
Title source: cnaDescription
CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, CoreWCF SAML 1.1 and SAML 2.0 token validation does not correctly resolve the issuer signing key or require signed tokens when IdentityConfiguration is used with federated bindings, allowing an unauthenticated remote attacker to impersonate any principal the trusted STS could issue. This issue is fixed in versions 1.8.1 and 1.9.1.
References (6)
Core 6
Core References
X_Refsource_Misc x_refsource_misc
https://github.com/CoreWCF/CoreWCF/releases/tag/v1.8.1
X_Refsource_Confirm x_refsource_confirm
https://github.com/CoreWCF/CoreWCF/security/advisories/GHSA-xjr9-gg9q-jx3v
X_Refsource_Misc x_refsource_misc
https://github.com/CoreWCF/CoreWCF/commit/0b8c8af851260e85e8402af53233d1b8f87dfb6f
X_Refsource_Misc x_refsource_misc
https://github.com/CoreWCF/CoreWCF/commit/0e63c2cca55763d8be6b226a234579280a09e7b6
X_Refsource_Misc x_refsource_misc
https://github.com/CoreWCF/CoreWCF/commit/e5cc9b6a4ecc102a50d782093bfc72e0790abe3d
X_Refsource_Misc x_refsource_misc
https://github.com/CoreWCF/CoreWCF/releases/tag/v1.9.1
Scores
CVSS v3
10.0
EPSS
0.0025
EPSS Percentile
16.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
total
Details
CWE
CWE-290
CWE-347
Status
published
Products (2)
CoreWCF/CoreWCF
< 1.8.1
CoreWCF/CoreWCF
>= 1.9.0, < 1.9.1
Published
Jul 08, 2026
Tracked Since
Jul 09, 2026