{"id":"CVE-2026-54782","aliases":["GHSA-xjr9-gg9q-jx3v"],"url":"https://o3.security/vulnerability/CVE-2026-54782","summary":"CoreWCF: Authentication bypass in CoreWCF SAML 1.1 / 2.0 token signature validation","details":"### Impact\nFull impersonation of any principal the trusted STS could have issued an assertion for — including administrative principals when the relying party grants them via SAML claims. Affects both SAML 1.1 and SAML 2.0.\n\n#### Preconditions\nRelying-party service is hosted with WSFederationHttpBinding or WS2007FederationHttpBinding (or any binding that triggers FederatedSecurityTokenManager for issued-token validation), and IdentityConfiguration is wired (UseIdentityConfiguration = true).\nAttacker can reach the service over the network and knows the trusted STS’s public certificate (public certs are by design discoverable).\n\n### Patches\nFixed in CoreWCF v1.8.1 and v1.9.1\n\n### Workarounds\nNone","published":"2026-07-08T22:20:37.401Z","modified":"2026-08-12T03:51:45.051876047Z","cvss":{"score":10,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N"},"epss":{"score":0.00414,"percentile":0.34956,"asOf":"2026-09-12"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"NuGet","name":"CoreWCF.Primitives","fixedVersion":"1.8.1"},{"ecosystem":"NuGet","name":"CoreWCF.Primitives","fixedVersion":"1.9.1"}],"fix":{"url":"https://github.com/CoreWCF/CoreWCF/commit/0b8c8af851260e85e8402af53233d1b8f87dfb6f","label":"CoreWCF/CoreWCF@0b8c8af"},"references":[{"type":"WEB","url":"https://github.com/CoreWCF/CoreWCF/releases/tag/v1.8.1"},{"type":"WEB","url":"https://github.com/CoreWCF/CoreWCF/releases/tag/v1.9.1"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/54xxx/CVE-2026-54782.json"},{"type":"ADVISORY","url":"https://github.com/CoreWCF/CoreWCF/security/advisories/GHSA-xjr9-gg9q-jx3v"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-54782"},{"type":"FIX","url":"https://github.com/CoreWCF/CoreWCF/commit/0b8c8af851260e85e8402af53233d1b8f87dfb6f"},{"type":"FIX","url":"https://github.com/CoreWCF/CoreWCF/commit/0e63c2cca55763d8be6b226a234579280a09e7b6"},{"type":"FIX","url":"https://github.com/CoreWCF/CoreWCF/commit/e5cc9b6a4ecc102a50d782093bfc72e0790abe3d"},{"type":"PACKAGE","url":"https://github.com/CoreWCF/CoreWCF"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:45.051876047Z"}}