CVE-2026-54784

CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. In version 1.9.0, CoreWCF SPNEGO SecurityContextToken negotiation can expose the proof key recovered from the RSTR when TransportWithMessageCredential with Windows client credentials and session establishment are used, allowing an observer to impersonate the authenticated Windows principal and decrypt or forge WS-SecureConversation traffic. This issue is fixed in version 1.9.1.
Configurations

No configuration.

History

08 Jul 2026, 23:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-08 23:16

Updated : 2026-07-10 05:16


NVD link : CVE-2026-54784

Mitre link : CVE-2026-54784

CVE.ORG link : CVE-2026-54784


JSON object : View

Products Affected

No product.

CWE
CWE-311

Missing Encryption of Sensitive Data

CWE-523

Unprotected Transport of Credentials