Junglewise Threat Intelligence

CVE-2026-78323: Red Hat JSS certificate validation bypass in JSSTrustManager

CVE-2026-78323 · Severity: medium · CVSS 6.5 · Published 2026-08-24

Vendors: Red Hat.

Executive brief

JSS (Java Security Services) is a cryptography library that handles certificate validation for secure connections. A flaw in the JSSTrustManager class allows improperly configured systems to accept untrusted CA certificates, potentially enabling attackers to intercept and forge secure communications. This risk is limited to non-default configurations where certificate revocation checking has been disabled.

Technical details

The vulnerability is an improper certificate validation flaw (CWE-295) in the JSSTrustManager class, which fails to verify NSS trust flags when validating CA certificates. An attacker can exploit this via network-based man-in-the-middle attacks to present forged certificates that will be accepted as trust anchors for TLS connections, but only when certificate revocation verification is explicitly disabled (isCertRevocationVerify set to false)—a non-standard configuration. Default configurations are protected by native revocation verification (certChainRevokeVerify). The server-side TLS path using TomcatJSS (JSSNativeTrustManager) is not affected. Patches are expected to address this issue in affected Red Hat products.

Affected products

  • Red Hat JSS <UNKNOWN>

Timeline

  • 2026-08-24: disclosed

References