Skip to content
Red HatCVE-2026-78323

Red Hat Certificate System 10: improper certificate validation

Medium6.5CVE-2026-78323 · Published Aug 24, 2026 · updated Aug 28, 2026

A flaw was found in JSS (Java Security Services). The JSSTrustManager class does not verify NSS trust flags when validating CA certificates, allowing certificates present in the NSS database without TRUSTED_CA flags to be accepted as trust anchors for TLS connections. In non-default configurations where certificate revocation checking is disabled, this could allow a man-in-the-middle attacker to forge certificates accepted by PKI client connections.

Red Hat advisory

Affected versions

PackageAffectedFixed in
Red Hat Certificate System 10
Product
all versionsNo fix yet
Red Hat Certificate System 11
Product
all versionsNo fix yet
Red Hat Enterprise Linux 10
Product
all versionsNo fix yet
Red Hat Enterprise Linux 6
Product
all versionsNo fix yet
Red Hat Enterprise Linux 7
Product
all versionsNo fix yet
Red Hat Enterprise Linux 8
Product
all versionsNo fix yet
Red Hat Enterprise Linux 9
Product
all versionsNo fix yet
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-295

More Red Hat advisories

All Red Hat
Advisory
A flaw was found in CRI-O's container-creation environment-variable handling
Medium6.0Aug 24
Red Hat GIMP: denial of service
Medium6.1Aug 24
Red Hat file-pcx plugin: integer overflow
High7.0Aug 24
Red Hat Enterprise Linux 10: improper authorization
High7.1Aug 24
Red Hat AWX: path traversal
High7.2Aug 24
Red Hat multiple AWX: server-side request forgery
High7.7Aug 24

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.