PT-2026-51078 · Corewcf+2 · Corewcf+1

CVE-2026-54781

·

Published

2026-06-19

·

Updated

2026-07-09

CVSS v3.1

7.4

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions CoreWCF versions prior to 1.8.1 CoreWCF versions prior to 1.9.1
Description SAML token validation in the SamlSecurityTokenHandler does not enforce SubjectConfirmation method URIs or holder-of-key proof keys. This allows an attacker to authenticate a subject without proving authority over the assertion through a holder-of-key downgrade or custom confirmation method assertions. In a holder-of-key downgrade, an attacker with a SAML assertion issued without KeyInfo can be authenticated without producing the required proof key. In a custom-method bypass, an attacker using a SAML assertion with a non-standard confirmation method URI can bypass per-method policies. This issue affects services configured to accept SAML 1.1 tokens via federation, typically using WS2007FederationHttpBinding, WSFederationHttpBinding, or custom bindings using IssuedSecurityTokenParameters with a SAML 1.1 token type.
Recommendations Update CoreWCF to version 1.8.1. Update CoreWCF to version 1.9.1.

Exploit

Fix

Improper Authentication

Insufficient Verification of Data Authenticity

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-54781
GHSA-48PQ-2XQ3-C2M4

Affected Products

Corewcf
Corewcf.Primitives