CVE-2026-54784

HIGH

CoreWCF: SPNEGO SecurityContextToken proof key wrapped without confidentiality

Title source: cna
STIX 2.1

Description

CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. In version 1.9.0, CoreWCF SPNEGO SecurityContextToken negotiation can expose the proof key recovered from the RSTR when TransportWithMessageCredential with Windows client credentials and session establishment are used, allowing an observer to impersonate the authenticated Windows principal and decrypt or forge WS-SecureConversation traffic. This issue is fixed in version 1.9.1.

Scores

CVSS v3 7.4
EPSS 0.0018
EPSS Percentile 7.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-311 CWE-523
Status published
Products (1)
CoreWCF/CoreWCF >= 1.9.0, < 1.9.1
Published Jul 08, 2026
Tracked Since Jul 09, 2026