Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
10.0

CVE-2026-54782: CoreWCF: Attackers can impersonate any user with admin privileges

GHSA-xjr9-gg9q-jx3v CVE-2026-54782 CVE-2026-54782
Summary

An attacker can use a known vulnerability in CoreWCF to pretend to be any user, including administrators, if they have access to the service and the trusted security token service's public certificate. This could allow them to access sensitive information or make changes to the system. To fix this issue, update to CoreWCF version 1.8.1 or 1.9.1.

What to do
  • Update corewcf.primitives to version 1.8.1.
  • Update corewcf.primitives to version 1.9.1.
Affected software
Ecosystem VendorProductAffected versions
nuget corewcf.primitives < 1.8.1
>= 1.9.0, < 1.9.1
Fix: upgrade to 1.8.1
corewcf corewcf >= 1.9.0, < 1.9.1
Original title
CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, CoreWCF SAML 1.1 and SAML 2.0 token validation does not correctly resolve the...
Original description
CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, CoreWCF SAML 1.1 and SAML 2.0 token validation does not correctly resolve the issuer signing key or require signed tokens when IdentityConfiguration is used with federated bindings, allowing an unauthenticated remote attacker to impersonate any principal the trusted STS could issue. This issue is fixed in versions 1.8.1 and 1.9.1.
ghsa CVSS3.1 10.0
Vulnerability type
CWE-290
CWE-347 Improper Verification of Cryptographic Signature
Published: 8 Jul 2026 · Updated: 20 Jul 2026 · First seen: 19 Jun 2026