PT-2026-51080 · Corewcf+2 · Corewcf+1

CVE-2026-54783

·

Published

2026-06-19

·

Updated

2026-07-10

CVSS v3.1

7.4

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions CoreWCF versions prior to 1.8.1 CoreWCF versions prior to 1.9.1
Description WS-Security signature verification fails to ensure that the selected ds:Signature covers the expected Security header target. This allows an attacker who has captured a signed SOAP envelope to replay arbitrary service operations while impersonating the victim principal for the duration of the signing key's validity. The DetectReplays setting on transport-security bindings is ineffective because the attack utilizes a fresh timestamp in the wsse:Security header, bypassing the replay-detection logic.
Recommendations Update to version 1.8.1. Update to version 1.9.1. Ensure communication is protected by SSL/TLS to prevent the capture of signed SOAP envelopes.

Exploit

Fix

Insufficient Verification of Data Authenticity

Improper Verification of Cryptographic Signature

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-54783
GHSA-GQV6-PWCG-87R8

Affected Products

Corewcf
Corewcf.Primitives