CVE-2026-54782
Deferred Deferred - Pending Action

SAML Token Validation Flaw in CoreWCF

Vulnerability report for CVE-2026-54782, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-08

Last updated on: 2026-07-10

Assigner: GitHub, Inc.

Description

CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, CoreWCF SAML 1.1 and SAML 2.0 token validation does not correctly resolve the issuer signing key or require signed tokens when IdentityConfiguration is used with federated bindings, allowing an unauthenticated remote attacker to impersonate any principal the trusted STS could issue. This issue is fixed in versions 1.8.1 and 1.9.1.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-08
Last Modified
2026-07-10
Generated
2026-07-11
AI Q&A
2026-07-09
EPSS Evaluated
2026-07-09
NVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
corewcf corewcf to 1.8.1 (inc)
corewcf corewcf to 1.9.1 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-347 The product does not verify, or incorrectly verifies, the cryptographic signature for data.
CWE-290 This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Compliance Impact

This vulnerability allows an unauthenticated remote attacker to impersonate any principal that a trusted Security Token Service (STS) could issue an assertion for, including potentially administrative users. Such unauthorized access can lead to a breach of confidentiality and integrity of protected data.

Because the flaw enables authentication bypass and unauthorized access to sensitive resources, it can negatively impact compliance with common security and privacy standards and regulations such as GDPR and HIPAA, which require strict controls on access to personal and sensitive information.

Organizations using affected CoreWCF versions prior to 1.8.1 and 1.9.1 may face increased risk of data breaches and unauthorized data access, potentially resulting in non-compliance with these regulations.

Upgrading to CoreWCF versions 1.8.1 or later is necessary to mitigate this risk and help maintain compliance with such standards.

Executive Summary

This vulnerability exists in CoreWCF, a port of the Windows Communication Foundation to .NET Core. Before versions 1.8.1 and 1.9.1, the SAML 1.1 and SAML 2.0 token validation did not properly resolve the issuer signing key or enforce that tokens were signed when using IdentityConfiguration with federated bindings.

Because of this, an unauthenticated remote attacker could impersonate any principal that the trusted Security Token Service (STS) could issue, effectively bypassing authentication controls.

This issue was fixed in CoreWCF versions 1.8.1 and 1.9.1.

Impact Analysis

The vulnerability allows an unauthenticated remote attacker to impersonate any user or principal that the trusted Security Token Service (STS) could issue tokens for.

This means an attacker could gain unauthorized access to systems or services that rely on CoreWCF for authentication, potentially leading to data breaches, unauthorized actions, or privilege escalation.

The CVSS score of 10.0 indicates a critical severity with network attack vector, no required privileges or user interaction, and high impact on confidentiality and integrity.

Mitigation Strategies

To mitigate this vulnerability, you should upgrade CoreWCF to version 1.8.1 or 1.9.1 or later, where the issue with SAML token validation is fixed.

Detection Guidance

There is no specific information provided in the available resources about commands or methods to detect this vulnerability on a network or system.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-54782. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart