CVE-2026-78323
Jss: jss: jsstrustmanager does not verify nss trust flags on ca certificates
CVSS Score
6.5
EPSS Score
0.0%
EPSS Percentile
0th
A flaw was found in JSS (Java Security Services). The JSSTrustManager class does not verify NSS trust flags when validating CA certificates, allowing certificates present in the NSS database without TRUSTED_CA flags to be accepted as trust anchors for TLS connections. In non-default configurations where certificate revocation checking is disabled, this could allow a man-in-the-middle attacker to forge certificates accepted by PKI client connections.
| CWE | CWE-295 |
| Vendor | red hat |
| Product | red hat certificate system 10 |
| Published | Aug 24, 2026 |
| Last Updated | Aug 24, 2026 |
Stay Ahead of the Next One
Get instant alerts for red hat red hat certificate system 10
Be the first to know when new medium vulnerabilities affecting red hat red hat certificate system 10 are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
Low
Availability
None
Affected Versions
Red Hat / Red Hat Certificate System 10
All versions affected Red Hat / Red Hat Certificate System 11
All versions affected Red Hat / Red Hat Enterprise Linux 10
All versions affected Red Hat / Red Hat Enterprise Linux 6
All versions affected Red Hat / Red Hat Enterprise Linux 7
All versions affected Red Hat / Red Hat Enterprise Linux 8
All versions affected Red Hat / Red Hat Enterprise Linux 9
All versions affected References
Credits
This issue was discovered by Marco Fargetta (Red Hat).