LIVE · cybersecurity feed
Live wire
cve recordhigh

CVE-2026-54774

Published
CVSS7.4
Severityhigh
WeaknessCWE-345
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

Description

CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, SamlSerializer skips final SignatureValue verification when a CoreWCF service validates SAML tokens using a non-X.509 signing token, allowing an attacker to reference a non-X.509 SecurityToken key identifier and bypass assertion signature verification. This issue is fixed in versions 1.8.1 and 1.9.1.

References

← Back to the CVE Tracker

Our coverage of CVE-2026-54774

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-54774.