CVE-2026-54782
Critical · CVSS 10.0CoreWCF.Primitives — SAML token signature validation bypass / authentication spoofing (CWE-290, CWE-347)
- CVSS
- 10.0
- nvd
- EPSS
- —
- KEV
- No
- Class
- oss containerizable
- CWE-290, CWE-347
Description
CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, CoreWCF SAML 1.1 and SAML 2.0 token validation does not correctly resolve the issuer signing key or require signed tokens when IdentityConfiguration is used with federated bindings, allowing an unauthenticated remote attacker to impersonate any principal the trusted STS could issue. This issue is fixed in versions 1.8.1 and 1.9.1.
Search profile — drives PoC discovery
Symbols IdentityConfigurationFederatedBindingSamlSecurityTokenHandlerSaml2SecurityTokenHandlerResolveIssuerSigningKeyRequireSignedTokensValidateTokenCoreWCF.SecurityCoreWCF.IdentityModelWSTrustTokenSerializerIssuedSecurityTokenParameters
Keywords CVE-2026-54782CoreWCF SAML token validation bypassCoreWCF authentication spoofingCoreWCF issuer signing keyCoreWCF federated binding SAMLCoreWCF IdentityConfigurationCoreWCF SAML impersonationCoreWCF 1.8.1 patchCoreWCF 1.9.1 patchCoreWCF SAML 1.1 SAML 2.0 unsigned tokenCoreWCF proof of concept
Versions: < 1.8.1 and < 1.9.1 (fixed in 1.8.1, 1.9.1)
Affected packages
| NuGet | CoreWCF.Primitives | 0 → 1.8.1 |
| NuGet | CoreWCF.Primitives | 1.9.0 → 1.9.1 |
References
- https://github.com/CoreWCF/CoreWCF/commit/0b8c8af851260e85e8402af53233d1b8f87dfb6f
- https://github.com/CoreWCF/CoreWCF/commit/0e63c2cca55763d8be6b226a234579280a09e7b6
- https://github.com/CoreWCF/CoreWCF/commit/e5cc9b6a4ecc102a50d782093bfc72e0790abe3d
- https://github.com/CoreWCF/CoreWCF/releases/tag/v1.8.1
- https://github.com/CoreWCF/CoreWCF/releases/tag/v1.9.1
- https://github.com/CoreWCF/CoreWCF/security/advisories/GHSA-xjr9-gg9q-jx3v
Status: enriched · ingested 2026-07-10T06:00:46.000Z · profiled 2026-07-10T06:30:26.000Z