{"id":"CVE-2026-54782","title":"CoreWCF: Authentication bypass in CoreWCF SAML 1.1 / 2.0 token signature validation","summary":"CoreWCF: Authentication bypass in CoreWCF SAML 1.1 / 2.0 token signature validation","severity":"critical","cvss":10,"cwe":["CWE-290","CWE-347"],"vendor":"CoreWCF","product":"CoreWCF.Primitives","ecosystem":"nuget","affected":["CoreWCF.Primitives < 1.8.1","CoreWCF.Primitives >= 1.9.0, < 1.9.1"],"patched":["CoreWCF.Primitives 1.8.1","CoreWCF.Primitives 1.9.1"],"published":"2026-06-19","updated":"2026-06-19","source":"GHSA","sourceUrl":"https://github.com/advisories/GHSA-xjr9-gg9q-jx3v","references":[{"url":"https://github.com/CoreWCF/CoreWCF/security/advisories/GHSA-xjr9-gg9q-jx3v"},{"url":"https://github.com/advisories/GHSA-xjr9-gg9q-jx3v"}],"tags":["ghsa","nuget"],"ingestedAt":"2026-06-22T13:35:24.422Z","epss":0.00414,"epssPercentile":0.35309,"slug":"CVE-2026-54782","body":"## Overview\n\n### Impact\nFull impersonation of any principal the trusted STS could have issued an assertion for — including administrative principals when the relying party grants them via SAML claims. Affects both SAML 1.1 and SAML 2.0.\n\n#### Preconditions\nRelying-party service is hosted with WSFederationHttpBinding or WS2007FederationHttpBinding (or any binding that triggers FederatedSecurityTokenManager for issued-token validation), and IdentityConfiguration is wired (UseIdentityConfiguration = true).\nAttacker can reach the service over the network and knows the trusted STS’s public certificate (public certs are by design discoverable).\n\n### Patches\nFixed in CoreWCF v1.8.1 and v1.9.1\n\n### Workarounds\nNone\n\n## Affected packages\n\n- `CoreWCF.Primitives < 1.8.1`\n- `CoreWCF.Primitives >= 1.9.0, < 1.9.1`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `CoreWCF.Primitives 1.8.1`\n- `CoreWCF.Primitives 1.9.1`","depth":"midnight","depthScore":55,"depthScoreParts":{"impact":55,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}