
Cloud Vulnerability DB
コミュニティ主導の脆弱性データベース
CVE-2026-54783 is an XML Signature Wrapping vulnerability in CoreWCF's WS-Security endorsing/supporting signature verification that allows replay of captured signed SOAP messages. It affects the CoreWCF.Primitives NuGet package versions 1.8.0 and 1.9.0. The vulnerability was published by maintainer mconnew on June 16, 2026, and added to the GitHub Advisory Database on June 19, 2026. It carries a CVSS v3.1 base score of 7.4 (High) (GitHub Advisory, CoreWCF Advisory).
The root cause is an XML Signature Wrapping (XSW) flaw in how CoreWCF verifies WS-Security endorsing and supporting signatures, classified under CWE-294 (Authentication Bypass by Capture-replay), CWE-345 (Insufficient Verification of Data Authenticity), and CWE-347 (Improper Verification of Cryptographic Signature). An attacker who captures a single legitimately signed SOAP envelope can replay it — with a freshly generated timestamp in the wsse:Security header — to impersonate the original victim. The replay-detection logic (DetectReplays) only inspects the timestamp field, which the attacker replaces, so it fails to detect the attack. There is no rate limiting on replays, meaning the attacker can invoke arbitrary service operations as the victim for the entire lifetime of the captured signing key (GitHub Advisory, CoreWCF Advisory).
A successful exploit allows an attacker to impersonate a legitimate victim principal and invoke arbitrary operations on the affected CoreWCF service with no privileges of their own. The impact includes high confidentiality loss (access to data the victim is authorized to retrieve) and high integrity loss (ability to submit unauthorized transactions or modifications on behalf of the victim). Availability is not directly impacted, but the persistent nature of the attack — lasting for the lifetime of the captured signing key with no replay rate limit — makes it particularly severe for services handling sensitive business logic or data (GitHub Advisory).
wsse:Security header containing the victim's XML digital signature and signing key reference.wsu:Timestamp in the wsse:Security header with a fresh, current timestamp to bypass the DetectReplays check.wsse:Security signature blocks but with updated timestamps.The primary remediation is to upgrade CoreWCF.Primitives to version 1.8.1 (for the 1.8.x branch) or 1.9.1 (for the 1.9.x branch), which contain the fix for this vulnerability. As an interim workaround, ensure all communication between clients and the CoreWCF service is protected by SSL/TLS, which prevents an attacker from capturing signed SOAP envelopes in the first place. Note that enabling the DetectReplays setting on transport-security bindings does not mitigate this issue and should not be relied upon as a compensating control (GitHub Advisory, CoreWCF Advisory).
ソース: このレポートは AI を使用して生成されました
無料の脆弱性評価
9つのセキュリティドメインにわたるクラウドセキュリティプラクティスを評価して、リスクレベルをベンチマークし、防御のギャップを特定します。
パーソナライズされたデモを見る
"私が今まで見た中で最高のユーザーエクスペリエンスは、クラウドワークロードを完全に可視化します。"
"Wiz を使えば、クラウド環境で何が起こっているかを 1 つの画面で確認することができます"
"Wizが何かを重要視した場合、それは実際に重要であることを私たちは知っています。"