CVE-2026-54782: CoreWCF: Authentication bypass in CoreWCF SAML 1.1 / 2.0 token signature validation
Full impersonation of any principal the trusted STS could have issued an assertion for — including administrative principals when the relying party grants them via SAML claims. Affects both SAML 1.1 and SAML 2.0.
References
Code Behaviors & Features
Detect and mitigate CVE-2026-54782 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →