CVE-2026-54782Critical· 10.0▾ MidnightCoreWCF: Authentication bypass in CoreWCF SAML 1.1 / 2.0 token signature validation
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 55 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 9.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via GHSA
0.2%
0.2% → 0.4%
Full impersonation of any principal the trusted STS could have issued an assertion for — including administrative principals when the relying party grants them via SAML claims. Affects both SAML 1.1 and SAML 2.0.
Relying-party service is hosted with WSFederationHttpBinding or WS2007FederationHttpBinding (or any binding that triggers FederatedSecurityTokenManager for issued-token validation), and IdentityConfiguration is wired (UseIdentityConfiguration = true). Attacker can reach the service over the network and knows the trusted STS’s public certificate (public certs are by design discoverable).
Fixed in CoreWCF v1.8.1 and v1.9.1
None
CoreWCF.Primitives < 1.8.1CoreWCF.Primitives >= 1.9.0, < 1.9.1Upgrade to a patched release:
CoreWCF.Primitives 1.8.1CoreWCF.Primitives 1.9.1Connected by shared product, vendor, weakness, or advisory.
CVE-2026-54773Medium· 5.9CoreWCF: WS-Security signature substitution via document-wide Signature lookup
CVE-2026-54774High· 7.4CoreWCF: SamlSerializer skips SignatureValue verification when SAML signing token is not an X.509 certificate
CVE-2026-54783High· 7.4CoreWCF: XML Signature Wrapping in WS-Security endorsing/supporting signature verification allows replay of captured signed messages
CVE-2026-54779Medium· 5.9CoreWCF: SAML token replay protection is inoperative
CVE-2026-54780Low· 3.7CoreWCF: WS-Security Reference DigestMethod Algorithm-Suite Bypass
CVE-2026-54781High· 7.4CoreWCF: SAML SubjectConfirmation methods and holder-of-key proof keys are not enforced