← All CVEs

CVE-2026-54782

critical · 10

CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, CoreWCF SAML 1.1 and SAML 2.0 token validation does not correctly resolve the issuer signing key or require signed tokens when IdentityConfiguration is used with federated bindings, allowing an unauthenticated remote attacker to impersonate any principal the trusted STS could issue. This issue is fixed in versions 1.8.1 and 1.9.1.

10
CVSS
0.4%
EPSS (exploit prob.)
35th
EPSS percentile
2026-07-08
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N

Weaknesses

CWE-290CWE-347

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2026-54782