{"id":"CVE-2026-54784","aliases":["GHSA-2288-8h3r-cqgg"],"url":"https://o3.security/vulnerability/CVE-2026-54784","summary":"CoreWCF: SPNEGO SecurityContextToken proof key wrapped without confidentiality","details":"### Impact\nWhen the proof key recovered from the RSTR can be observed by a party that is not the legitimate client, that party can impersonate the authenticated Windows principal for the lifetime of the SCT (default ~10 hours) and decrypt or forge any subsequent WS‑SecureConversation traffic that uses keys derived from the SCT.\n\n#### Preconditions\nUsing security mode TransportWithMessageCredential with client credential type Windows, along with session establishment (which triggers use of WS-SecureConversation).\n\n### Patches\nFixed in CoreWCF v1.9.1\n\n### Workarounds\nEnsure communication is protected by SSL/TLS to prevent capturing of SCT negotiation handshake.","published":"2026-07-08T22:18:13.846Z","modified":"2026-08-12T03:51:27.103513452Z","cvss":{"score":7.4,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"},"epss":{"score":0.00272,"percentile":0.19541,"asOf":"2026-09-12"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"NuGet","name":"CoreWCF.Primitives","fixedVersion":"1.9.1"}],"fix":{"url":"https://github.com/CoreWCF/CoreWCF/commit/2afae08b2fa5288428df89e8161116b816cf6b4b","label":"CoreWCF/CoreWCF@2afae08"},"references":[{"type":"WEB","url":"https://github.com/CoreWCF/CoreWCF/releases/tag/v1.9.1"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/54xxx/CVE-2026-54784.json"},{"type":"ADVISORY","url":"https://github.com/CoreWCF/CoreWCF/security/advisories/GHSA-2288-8h3r-cqgg"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-54784"},{"type":"FIX","url":"https://github.com/CoreWCF/CoreWCF/commit/2afae08b2fa5288428df89e8161116b816cf6b4b"},{"type":"FIX","url":"https://github.com/CoreWCF/CoreWCF/commit/f216aa6929d41dc99cee098b1e69c260ec4c41c7"},{"type":"PACKAGE","url":"https://github.com/CoreWCF/CoreWCF"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:27.103513452Z"}}