PT-2026-51076 · Corewcf+2 · Corewcf+1
CVE-2026-54779
·
Published
2026-06-19
·
Updated
2026-07-09
CVSS v3.1
5.9
Medium
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
CoreWCF versions prior to 1.8.1
CoreWCF versions prior to 1.9.1
Description
SAML token replay protection is inoperative because the
DefaultTokenReplayCache.TryAdd() function does not reject duplicate tokens when DetectReplayedTokens is enabled. This allows a captured token to be reused.Recommendations
Update to version 1.8.1.
Update to version 1.9.1.
Provide a custom implementation of
ITokenReplayCache with the correct behavior.Exploit
Fix
Insufficient Session Expiration
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Corewcf
Corewcf.Primitives