CVE-2026-54773: CoreWCF: WS-Security signature substitution via document-wide Signature lookup
An unauthenticated remote attacker who can place a SOAP header lexically before wsse:Security can embed a ds:Signature of their choosing inside that header and cause the server to verify the attacker-supplied signature instead of the one carried in the security header.
References
Code Behaviors & Features
Detect and mitigate CVE-2026-54773 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →