Junglewise Threat Intelligence

CVE-2026-54774: CoreWCF SAML signature bypass in SamlSerializer

CVE-2026-54774 · Severity: high · CVSS 7.4 · Published 2026-07-08

Technologies: CoreWCF. Vendors: CoreWCF.

Executive brief

CoreWCF, a tool used to run Windows Communication Foundation services on modern .NET platforms, contains a security flaw in how it verifies digital signatures for SAML identity tokens. When a service is configured to use certain types of security keys, an attacker can bypass the signature check by providing a forged token. This could allow an unauthorized user to impersonate others or gain elevated access to the service and its data.

Technical details

A vulnerability exists in CoreWCF's SamlSerializer.ReadToken method where signature verification logic branches based on the token type. While X509SecurityTokens undergo full XML-DSig verification, other token types (such as symmetric proof-keys used in WS-Trust scenarios) only trigger a digest-only verification of the SignedInfo block. This root cause allows an attacker to author a SAML assertion, compute the Reference DigestValue, and provide an arbitrary SignatureValue that is never cryptographically validated against a key. The issue is reachable when using WSSecurityTokenSerializer with an out-of-band issuer-token resolver containing non-X.509 tokens. The vulnerability is fixed in versions 1.8.1 and 1.9.1 by ensuring full key-based verification for all supported security key types.

Affected products

  • CoreWCF CoreWCF < 1.8.1, >= 1.9.0 < 1.9.1

Timeline

  • 2026-07-08: disclosed
  • 2026-07-08: advisory

References

Related threats