
PEACH
Un cadre d’isolation des locataires
CVE-2026-54783 is an XML Signature Wrapping vulnerability in CoreWCF's WS-Security endorsing/supporting signature verification that allows replay of captured signed SOAP messages. It affects the CoreWCF.Primitives NuGet package versions 1.8.0 and 1.9.0 (i.e., versions prior to 1.8.1 and prior to 1.9.1). The vulnerability was published by the CoreWCF maintainer on June 16, 2026, and added to the GitHub Advisory Database on June 19, 2026. It carries a CVSS v3.1 base score of 7.4 (High) (GitHub Advisory, CoreWCF Advisory).
The root cause is an XML Signature Wrapping (XSW) flaw in how CoreWCF verifies WS-Security endorsing and supporting signatures, classified under CWE-294 (Authentication Bypass by Capture-replay), CWE-345 (Insufficient Verification of Data Authenticity), and CWE-347 (Improper Verification of Cryptographic Signature). An attacker who captures a single legitimately signed SOAP envelope can replay it — with a freshly generated timestamp in the wsse:Security header — to impersonate the original victim principal. The replay-detection logic (DetectReplays) only inspects the timestamp field, which the attacker replaces with a fresh value, effectively bypassing the anti-replay mechanism entirely. There is no rate limiting on replays, meaning the attack can be repeated indefinitely for the lifetime of the captured signing key (GitHub Advisory, CoreWCF Advisory).
A successful exploit allows an unauthenticated attacker to invoke arbitrary SOAP operations on the affected service while impersonating a legitimate victim principal, resulting in high confidentiality and integrity impact. The attacker can read sensitive data accessible to the victim's account and perform unauthorized write or transactional operations on the service. Availability is not directly impacted, but the ability to act as any captured principal could enable lateral movement within service-oriented architectures that trust WS-Security identity assertions (GitHub Advisory).
CoreWCF.Primitives versions 1.8.0 or 1.9.0 that use WS-Security message-level signing without mandatory SSL/TLS transport protection.wsse:Security header containing the digital signature and the original timestamp.wsu:Timestamp element in the wsse:Security header with a fresh, current timestamp while preserving the original signature over the message body and other signed elements.wsse:Security header.wsu:Timestamp values that are always near-current but whose message body signatures correspond to a previously observed signed message.Upgrade CoreWCF.Primitives to version 1.8.1 or 1.9.1, which contain the fix for this vulnerability. As an immediate workaround where upgrading is not possible, enforce SSL/TLS transport-layer encryption on all CoreWCF service endpoints to prevent attackers from capturing signed SOAP envelopes in transit. Note that enabling the DetectReplays setting alone does not mitigate this issue, as the attack uses a fresh timestamp that bypasses that check (GitHub Advisory, CoreWCF Advisory).
Source: Ce rapport a été généré à l’aide de l’IA
Évaluation gratuite des vulnérabilités
Évaluez vos pratiques de sécurité cloud dans 9 domaines de sécurité pour évaluer votre niveau de risque et identifier les failles dans vos défenses.
Obtenez une démo personnalisée
"La meilleure expérience utilisateur que j’ai jamais vue, offre une visibilité totale sur les workloads cloud."
"Wiz fournit une interface unique pour voir ce qui se passe dans nos environnements cloud."
"Nous savons que si Wiz identifie quelque chose comme critique, c’est qu’il l’est réellement."