CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2026-54782

Critical · CVSS 10.0

CoreWCF.Primitives — SAML token signature validation bypass / authentication spoofing (CWE-290, CWE-347)

CVSS
10.0
nvd
EPSS
KEV
No
Class
oss containerizable
CWE-290, CWE-347

Description

CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, CoreWCF SAML 1.1 and SAML 2.0 token validation does not correctly resolve the issuer signing key or require signed tokens when IdentityConfiguration is used with federated bindings, allowing an unauthenticated remote attacker to impersonate any principal the trusted STS could issue. This issue is fixed in versions 1.8.1 and 1.9.1.

Search profile — drives PoC discovery

Symbols IdentityConfigurationFederatedBindingSamlSecurityTokenHandlerSaml2SecurityTokenHandlerResolveIssuerSigningKeyRequireSignedTokensValidateTokenCoreWCF.SecurityCoreWCF.IdentityModelWSTrustTokenSerializerIssuedSecurityTokenParameters
Keywords CVE-2026-54782CoreWCF SAML token validation bypassCoreWCF authentication spoofingCoreWCF issuer signing keyCoreWCF federated binding SAMLCoreWCF IdentityConfigurationCoreWCF SAML impersonationCoreWCF 1.8.1 patchCoreWCF 1.9.1 patchCoreWCF SAML 1.1 SAML 2.0 unsigned tokenCoreWCF proof of concept
Versions: < 1.8.1 and < 1.9.1 (fixed in 1.8.1, 1.9.1)

Affected packages

NuGet CoreWCF.Primitives 0 → 1.8.1
NuGet CoreWCF.Primitives 1.9.0 → 1.9.1

References

Status: enriched · ingested 2026-07-10T06:00:46.000Z · profiled 2026-07-10T06:30:26.000Z