CVE-2026-54779: CoreWCF SAML Token Replay Protection Bypass
CoreWCF, a .NET Core implementation of Windows Communication Foundation, contains a flaw in its SAML token replay protection mechanism. When replay detection is enabled, the system fails to reject tokens that have already been used, allowing an attacker who intercepts a valid token to replay it multiple times. This undermines the security guarantee that tokens should only be valid once, potentially allowing unauthorized access even after the original user's session should have expired.
Source data · NVD / CISA · public domain
- CVSS
- 3.1 · 5.9 MEDIUM · CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
- Weaknesses (CWE)
- CWE-294, CWE-613
- Affected products
- 0 configuration(s)
- Published / Modified
- 2026-07-08 / 2026-07-09
NVD description (verbatim)
CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, CoreWCF SAML token replay protection is inoperative because DefaultTokenReplayCache.TryAdd does not reject duplicate tokens when DetectReplayedTokens is enabled, allowing a captured token to be reused. This issue is fixed in versions 1.8.1 and 1.9.1.
6 reference(s) · View on NVD →
SEC.co analysis · AI-assisted, reviewed against source
Technical summary
The vulnerability exists in the DefaultTokenReplayCache.TryAdd method of CoreWCF versions prior to 1.8.1 and 1.9.1. When DetectReplayedTokens is configured to true, the replay cache fails to detect and reject duplicate SAML tokens. The TryAdd operation does not perform proper duplicate detection, meaning a previously-cached token can be added again without triggering a rejection. This breaks the replay protection contract and allows tokens to be reused indefinitely, violating the intended one-time-use semantics of SAML authentication tokens.
Business impact
Token replay attacks can lead to unauthorized access to protected resources and services. An attacker with a captured SAML token can impersonate legitimate users without needing credentials or re-authentication. In environments where SAML tokens are long-lived or carry sensitive permissions, this creates a persistent authentication bypass. The impact is especially severe in multi-tenant or federated identity scenarios where a single token compromise could affect multiple integrated systems.
Affected systems
CoreWCF versions prior to 1.8.1 (1.8.0 and earlier) and 1.9.0 are affected. The vulnerability only manifests when the DetectReplayedTokens security feature is explicitly enabled. Applications using CoreWCF for SAML-based authentication with replay detection active are at risk. Note that this affects the open-source CoreWCF project; verify your dependency tree to confirm exposure.
Exploitability
Exploitation requires network access and a captured or intercepted SAML token, making the attack vector network-based but with elevated complexity due to the need to obtain a valid token first. No authentication or user interaction is required once a token is obtained. The attack is deterministic once preconditions are met—there is no race condition or timing sensitivity. The CVSS score of 5.9 (MEDIUM) reflects the integrity impact (unauthorized access) against the constraint that a token must first be captured.
Remediation
Upgrade CoreWCF to version 1.8.1 or later if using the 1.8.x branch, or to version 1.9.1 or later if using the 1.9.x branch. These versions restore proper duplicate detection in the token replay cache. If immediate patching is not possible, disable SAML token processing or review whether DetectReplayedTokens can be temporarily disabled, though this reduces security posture and is not recommended as a permanent workaround.
Patch guidance
Apply the security update to CoreWCF by updating your NuGet package reference to version 1.8.1 or 1.9.1 (or later). Review your project dependencies to ensure all direct and transitive references to vulnerable CoreWCF versions are updated. Verify compatibility with your application after patching, though these are maintenance releases and should not introduce breaking changes. For teams using a corporate NuGet feed, work with package management to stage and validate the update before broad deployment.
Detection guidance
Monitor for repeated use of the same SAML token in authentication logs or token validation events, especially if tokens appear in different sessions or contexts. Examine CoreWCF configuration to confirm DetectReplayedTokens is enabled; if it is not set explicitly, verify the default behavior in your version. Review audit logs for suspicious patterns such as the same token appearing in multiple authentication events within a short time window. Consider instrumenting the DefaultTokenReplayCache to log cache hits and misses.
Why prioritize this
This vulnerability enables persistent authentication bypass for SAML-based services. The combination of network-accessible attack surface and integrity-level impact (unauthorized access) justifies prompt patching. While the CVSS score is MEDIUM, the nature of the flaw—defeating a security control that is often explicitly enabled for compliance reasons—elevates its practical priority. Organizations relying on SAML federation for access control should treat this as high-priority.
Risk score, explained
CVSS 5.9 reflects network accessibility (AV:N) and integrity impact (I:H) without requiring authentication or user interaction. The elevated complexity (AC:H) accounts for the attacker needing to first capture a valid token. The lack of confidentiality or availability impact limits the score to MEDIUM. However, the qualitative risk is elevated for organizations where SAML tokens are a critical authentication trust anchor.
Frequently asked questions
If we are not using SAML tokens in our CoreWCF services, are we affected?
No. This vulnerability is specific to SAML token handling and the replay cache. If your CoreWCF deployment uses other authentication methods (such as username/password or certificate-based), you are not affected by this flaw.
What happens if DetectReplayedTokens is not enabled?
The replay protection feature is opt-in via the DetectReplayedTokens configuration. If it is not enabled, the vulnerable code path is not exercised, and tokens can be reused by design. However, disabling replay detection removes an important security control and is not recommended as a mitigation.
Can we detect if this vulnerability has been exploited in our environment?
Look for evidence of token reuse in authentication logs—specifically, the same token appearing in multiple authentication events or sessions. Correlate SAML assertion IDs or token identifiers with login timestamps. If you see the same token ID used hours or days apart, that is a strong signal of replay activity.
Are there any known public exploits for this vulnerability?
As of the publication date, there is no evidence of widespread public exploitation. However, the exploit technique is straightforward for an attacker with a captured token, so do not rely on obscurity. Prioritize patching based on your own environment's token exposure and sensitivity.
This analysis is based on the CVE record and vendor advisory as of the publication date. Exploit techniques and threat landscape may evolve. Verify all patch versions and upgrade instructions directly with the CoreWCF project and your vendor. This summary does not constitute legal, compliance, or specific technical advice; consult your security team and the official vendor guidance before making remediation decisions. Source: NVD (public-domain), retrieved 2026-08-17. Analysis generated by SEC.co (claude-haiku-4-5).
Related vulnerabilities
- CVE-2023-33854MEDIUMIBM Db2 MITM Input Validation Bypass – Patch Guidance
- CVE-2026-12772MEDIUMSession Expiration Flaw in BerriAI litellm Proxy Authentication
- CVE-2026-12796MEDIUMlitellm SSO Session Expiration Vulnerability (CVSS 6.3)
- CVE-2026-14725MEDIUMSourceCodester Boat Reservation System Session Expiration Vulnerability
- CVE-2026-44188MEDIUMAnsible Lightspeed Session Hijacking via Token Non-Revocation
- CVE-2026-46538MEDIUMMicrosoft UFO Cross-Device Task Result Injection (CVSS 5.9)
- CVE-2026-47341MEDIUMApache APISIX Authentication Bypass via Token Replay
- CVE-2026-48726MEDIUMApache Airflow JWT Token Revocation Bypass in FAB and Keycloak Logout