PT-2026-51081 · Corewcf+2 · Corewcf+1
CVE-2026-54784
·
Published
2026-06-19
·
Updated
2026-07-10
CVSS v3.1
7.4
High
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
CoreWCF versions prior to 1.9.1
Description
CoreWCF SPNEGO SecurityContextToken (SCT) negotiation can expose the proof key recovered from the RSTR when TransportWithMessageCredential with Windows client credentials and session establishment are used. This allows an observer to impersonate the authenticated Windows principal for the lifetime of the SCT (typically around 10 hours) and decrypt or forge WS-SecureConversation traffic. This occurs when the security mode is set to TransportWithMessageCredential with Windows client credential type and session establishment is enabled, triggering the use of WS-SecureConversation.
Recommendations
Update to version 1.9.1.
Ensure communication is protected by SSL/TLS to prevent capturing of the SCT negotiation handshake.
Exploit
Fix
Missing Encryption of Sensitive Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Corewcf
Corewcf.Primitives