PT-2026-51079 · Corewcf+2 · Corewcf+1

CVE-2026-54782

·

Published

2026-06-19

·

Updated

2026-07-17

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions CoreWCF versions prior to 1.8.1 CoreWCF versions prior to 1.9.1
Description SAML 1.1 and SAML 2.0 token validation fails to correctly resolve the issuer signing key or enforce signed tokens when IdentityConfiguration is used with federated bindings. This occurs when the service is hosted with WSFederationHttpBinding or WS2007FederationHttpBinding, or any binding that triggers FederatedSecurityTokenManager for issued-token validation, and UseIdentityConfiguration is set to true. An unauthenticated remote attacker who knows the trusted Security Token Service (STS) public certificate can impersonate any principal the trusted STS could issue, including administrative principals.
Recommendations Update CoreWCF to version 1.8.1. Update CoreWCF to version 1.9.1.

Exploit

Fix

Improper Verification of Cryptographic Signature

Authentication Bypass by Spoofing

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-54782
GHSA-XJR9-GG9Q-JX3V

Affected Products

Corewcf
Corewcf.Primitives