
Cloud Vulnerability DB
コミュニティ主導の脆弱性データベース
CVE-2026-54784 is a cryptographic flaw in CoreWCF (the open-source .NET implementation of WCF) where the SPNEGO SecurityContextToken (SCT) proof key is wrapped without confidentiality protection during WS-SecureConversation session establishment. An attacker who can observe the Request Security Token Response (RSTR) can recover the proof key and subsequently impersonate the authenticated Windows principal for the lifetime of the SCT (default ~10 hours). The vulnerability affects CoreWCF.Primitives NuGet package versions >= 1.9.0 and < 1.9.1. It was published on June 16, 2026, and carries a CVSS v3.1 base score of 7.4 (High) (GitHub Advisory, CoreWCF Advisory).
The root cause is classified under CWE-311 (Missing Encryption of Sensitive Data) and CWE-523 (Unprotected Transport of Credentials). During WS-SecureConversation session establishment using SPNEGO with TransportWithMessageCredential security mode and Windows client credential type, the proof key included in the RSTR is not wrapped with confidentiality protection. This means any network-adjacent party capable of intercepting the SCT negotiation handshake can extract the proof key in plaintext. The attack requires high complexity (network interception of the handshake), no privileges, and no user interaction, but is limited to deployments using the specific security mode and credential type combination (GitHub Advisory, CoreWCF Advisory).
A successful attacker who recovers the proof key can impersonate the authenticated Windows principal for the full SCT lifetime (approximately 10 hours by default), and can decrypt or forge any subsequent WS-SecureConversation traffic whose session keys are derived from the compromised SCT. This results in high confidentiality and integrity impact — sensitive business data transmitted over the WCF channel can be read or tampered with — though availability is not directly affected. The scope is limited to services configured with TransportWithMessageCredential and Windows credentials using session-based security (GitHub Advisory).
TransportWithMessageCredential security mode and Windows client credential type, which trigger WS-SecureConversation session establishment.The vulnerability is fixed in CoreWCF v1.9.1 (NuGet package CoreWCF.Primitives); upgrading to this version is the recommended remediation (GitHub Advisory, CoreWCF Advisory). As a workaround for deployments that cannot immediately upgrade, ensure all communication between WCF clients and servers is protected by SSL/TLS, which prevents an attacker from capturing the SCT negotiation handshake and observing the proof key. Organizations should also audit their CoreWCF service configurations to confirm whether TransportWithMessageCredential with Windows credentials and session establishment is in use, as only those deployments are affected.
ソース: このレポートは AI を使用して生成されました
無料の脆弱性評価
9つのセキュリティドメインにわたるクラウドセキュリティプラクティスを評価して、リスクレベルをベンチマークし、防御のギャップを特定します。
パーソナライズされたデモを見る
"私が今まで見た中で最高のユーザーエクスペリエンスは、クラウドワークロードを完全に可視化します。"
"Wiz を使えば、クラウド環境で何が起こっているかを 1 つの画面で確認することができます"
"Wizが何かを重要視した場合、それは実際に重要であることを私たちは知っています。"