CVE-2026-54784CWE-311CWE-523

CoreWCF: SPNEGO SecurityContextToken proof key wrapped without confidentiality

High · published July 8, 2026

CVSS v3.1
7.4
EPSS
0%
Percentile
19.3
In the wild
Unconfirmed
What it is

CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. In version 1.9.0, CoreWCF SPNEGO SecurityContextToken negotiation can expose the proof key recovered from the RSTR when TransportWithMessageCredential with Windows client credentials and session establishment are used, allowing an observer to impersonate the authenticated Windows principal and decrypt or forge WS-SecureConversation traffic. This issue is fixed in version 1.9.1.

The record
Technical detail
CVSS v3.1
7.4 · HIGH
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
CVSS v4.0
Not supplied
EPSS
0.00272 · 19.3th percentile
Weaknesses
CWE-311 · Missing Encryption of Sensitive Data; CWE-523 · Unprotected Transport of Credentials
Published
2026-07-08T22:18Z
EPSS history
Timeline
  • 08 JUL 22:18Z
    CoreWCF: SPNEGO SecurityContextToken proof key wrapped without confidentiality
    cvelistv5