PT-2026-51078 · Corewcf+2 · Corewcf+1
CVE-2026-54781
·
Published
2026-06-19
·
Updated
2026-07-09
CVSS v3.1
7.4
High
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
CoreWCF versions prior to 1.8.1
CoreWCF versions prior to 1.9.1
Description
SAML token validation in the
SamlSecurityTokenHandler does not enforce SubjectConfirmation method URIs or holder-of-key proof keys. This allows an attacker to authenticate a subject without proving authority over the assertion through a holder-of-key downgrade or custom confirmation method assertions. In a holder-of-key downgrade, an attacker with a SAML assertion issued without KeyInfo can be authenticated without producing the required proof key. In a custom-method bypass, an attacker using a SAML assertion with a non-standard confirmation method URI can bypass per-method policies. This issue affects services configured to accept SAML 1.1 tokens via federation, typically using WS2007FederationHttpBinding, WSFederationHttpBinding, or custom bindings using IssuedSecurityTokenParameters with a SAML 1.1 token type.Recommendations
Update CoreWCF to version 1.8.1.
Update CoreWCF to version 1.9.1.
Exploit
Fix
Improper Authentication
Insufficient Verification of Data Authenticity
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Corewcf
Corewcf.Primitives