PT-2026-51071 · Corewcf+2 · Corewcf+1

CVE-2026-54774

·

Published

2026-06-19

·

Updated

2026-07-10

CVSS v3.1

7.4

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions CoreWCF versions prior to 1.8.1 CoreWCF versions prior to 1.9.1
Description The SamlSerializer skips the final SignatureValue verification when a service validates SAML tokens using a non-X.509 signing token. This occurs when the service is configured to authenticate using SAML tokens and an out-of-band token resolver holds a non-X.509 SecurityToken whose key identifier can be referenced in the assertion's <KeyInfo>, such as a BinarySecretSecurityToken representing a symmetric proof key. This allows an attacker to bypass assertion signature verification.
Recommendations Update CoreWCF to version 1.8.1. Update CoreWCF to version 1.9.1.

Exploit

Fix

Insufficient Verification of Data Authenticity

Improper Verification of Cryptographic Signature

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-54774
GHSA-RPJ7-HR7H-W6P9

Affected Products

Corewcf
Corewcf.Primitives