{"id":"CVE-2026-54784","title":"CoreWCF: SPNEGO SecurityContextToken proof key wrapped without confidentiality","summary":"CoreWCF: SPNEGO SecurityContextToken proof key wrapped without confidentiality","severity":"high","cvss":7.4,"cwe":["CWE-311","CWE-523"],"vendor":"CoreWCF","product":"CoreWCF.Primitives","ecosystem":"nuget","affected":["CoreWCF.Primitives >= 1.9.0, < 1.9.1"],"patched":["CoreWCF.Primitives 1.9.1"],"published":"2026-06-19","updated":"2026-06-19","source":"GHSA","sourceUrl":"https://github.com/advisories/GHSA-2288-8h3r-cqgg","references":[{"url":"https://github.com/CoreWCF/CoreWCF/security/advisories/GHSA-2288-8h3r-cqgg"},{"url":"https://github.com/advisories/GHSA-2288-8h3r-cqgg"}],"tags":["ghsa","nuget"],"ingestedAt":"2026-06-22T13:35:24.418Z","epss":0.00272,"epssPercentile":0.19784,"slug":"CVE-2026-54784","body":"## Overview\n\n### Impact\nWhen the proof key recovered from the RSTR can be observed by a party that is not the legitimate client, that party can impersonate the authenticated Windows principal for the lifetime of the SCT (default ~10 hours) and decrypt or forge any subsequent WS‑SecureConversation traffic that uses keys derived from the SCT.\n\n#### Preconditions\nUsing security mode TransportWithMessageCredential with client credential type Windows, along with session establishment (which triggers use of WS-SecureConversation).\n\n### Patches\nFixed in CoreWCF v1.9.1\n\n### Workarounds\nEnsure communication is protected by SSL/TLS to prevent capturing of SCT negotiation handshake.\n\n## Affected packages\n\n- `CoreWCF.Primitives >= 1.9.0, < 1.9.1`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `CoreWCF.Primitives 1.9.1`","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":40.7,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}