Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Marco Fargetta

#43735of 56,330
6.5Total CVSS
Vulnerabilities · 1
PT-2026-80803
6.5
2026-08-24
Jss · Jss · CVE-2026-78323
**Name of the Vulnerable Software and Affected Versions** JSS (Java Security Services) (affected versions not specified) **Description** A flaw exists in the `JSSTrustManager` class where it fails to verify NSS trust flags during the validation of CA certificates. This allows certificates in the NSS database that lack `TRUSTED CA` flags to be accepted as trust anchors for TLS connections. In non-default configurations where certificate revocation checking is disabled, a man-in-the-middle attacker could forge certificates that are accepted by PKI client connections. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability.