Junglewise Threat Intelligence

CVE-2026-54773: CoreWCF improper signature verification in WS-Security

CVE-2026-54773 · Severity: medium · CVSS 5.9 · Published 2026-07-08

Technologies: CoreWCF. Vendors: CoreWCF.

Executive brief

CoreWCF is a library used to build web services in .NET applications. A security flaw in how it verifies digital signatures could allow an attacker to bypass security checks by providing their own signature in a specially crafted message. This could lead to the service accepting unauthorized or tampered data as if it were legitimate.

Technical details

A signature verification vulnerability exists in CoreWCF's WS-Security implementation. The 'WSSecurityOneDotZeroReceiveSecurityHeader' component performs a document-wide 'ds:Signature' lookup rather than restricting the search to the 'wsse:Security' header. An unauthenticated remote attacker can exploit this by placing a SOAP header before the security header, causing the system to verify an attacker-controlled signature instead of the intended one. This is classified as improper verification of cryptographic signatures (CWE-347). The issue is resolved in versions 1.8.1 and 1.9.1 by binding the signature lookup specifically to the Security header subtree.

Affected products

  • CoreWCF CoreWCF < 1.8.1, >= 1.9.0 < 1.9.1

Timeline

  • 2026-07-08: advisory: NVD publication date
  • 2026-07-08: disclosed: GitHub Security Advisory published
  • 2026-06-16: patched: Fix committed to repository

References

Related threats