Jss · Jss · CVE-2026-78323
**Name of the Vulnerable Software and Affected Versions**
JSS (Java Security Services) (affected versions not specified)
**Description**
A flaw exists in the `JSSTrustManager` class where it fails to verify NSS trust flags during the validation of CA certificates. This allows certificates in the NSS database that lack `TRUSTED CA` flags to be accepted as trust anchors for TLS connections. In non-default configurations where certificate revocation checking is disabled, a man-in-the-middle attacker could forge certificates that are accepted by PKI client connections.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.