Junglewise Threat Intelligence

CVE-2026-54782: CoreWCF authentication bypass in SAML token validation

CVE-2026-54782 · Severity: critical · CVSS 10 · Published 2026-07-08

Technologies: CoreWCF. Vendors: CoreWCF.

Executive brief

CoreWCF is a modern version of a Microsoft framework used by developers to build networked applications. A security flaw in how it handles login tokens (SAML) allows an attacker to bypass security checks and pretend to be any user. This could lead to unauthorized access to sensitive data or administrative functions without needing a valid password or signature.

Technical details

A vulnerability exists in CoreWCF's SAML 1.1 and SAML 2.0 token validation logic when using IdentityConfiguration with federated bindings. The root cause is a failure to correctly resolve the issuer signing key and a lack of enforcement for signed tokens. An unauthenticated remote attacker can exploit this by providing an unsigned or improperly signed token to impersonate any user or principal that the trusted Security Token Service (STS) is authorized to issue. This is classified as an authentication bypass by spoofing (CWE-290) and improper verification of cryptographic signatures (CWE-347). The issue is resolved in versions 1.8.1 and 1.9.1 by requiring signed tokens and implementing a proper IssuerSigningKeyResolver.

Affected products

  • CoreWCF CoreWCF < 1.8.1, >= 1.9.0 < 1.9.1

Timeline

  • 2026-07-08: disclosed
  • 2026-07-08: advisory

References

Related threats