SecBoard
Zurück zur CVE-Übersicht

CVE-2026-54782

CRITICAL(10.0)

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N

Risk Signal Score25/100 — MITTEL
  • CVSS 10 — Kritisch

EPSS-Score

0.4%

Exploit-Wahrscheinlichkeit (30 Tage)

CVSS Score

10

Technische Schwere

Beschreibung

CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, CoreWCF SAML 1.1 and SAML 2.0 token validation does not correctly resolve the issuer signing key or require signed tokens when IdentityConfiguration is used with federated bindings, allowing an unauthenticated remote attacker to impersonate any principal the trusted STS could issue. This issue is fixed in versions 1.8.1 and 1.9.1.

GitHub Advisories

GHSA-xjr9-gg9q-jx3vCRITICAL

CoreWCF: Authentication bypass in CoreWCF SAML 1.1 / 2.0 token signature validation

nuget/CoreWCF.Primitives→ 1.8.1
GitHub Advisory

Referenzen