Sceawere

Vulnerability Detail

CVE-2026-102666UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Joyland AI Hard-Coded Credentials

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.5
Creation Date
1d ago
Vendor
Joyland
Product
Joyland.ai
Attack Type
CWE-798 Use of Hard-coded Credentials
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

The Joyland AI app contains hard-coded credentials for the GeTui push notification service, allowing an attacker to access the GeTui REST API and send push notifications containing arbitrary content to any user, group of users, or all users of the app at once.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.5",
  "pubDate": "2026-10-01T20:17:21.610Z",
  "pubdate": "2026-10-01T20:17:21.610Z",
  "executiveSummary": "The Joyland AI application contains hard-coded credentials for the GeTui push notification service, introducing a significant security vulnerability. This flaw involves the embedding of sensitive API authentication tokens directly within the application binary, which allows unauthorized access to the GeTui REST API infrastructure. By leveraging these exposed credentials, an attacker can bypass standard authentication mechanisms to interact directly with the push notification gateway associated with the application. The primary impact of this vulnerability is the ability to perform unauthorized message injection, enabling an attacker to send arbitrary push notifications to any subset or the entire user base of the Joyland AI application. This poses severe risks, including the potential for mass phishing attacks, the dissemination of malicious links, and the delivery of misleading information to users, thereby compromising the integrity of the application's communication channel and eroding user trust in the platform's security posture. No specialized access or user interaction is required for an attacker to initiate this exploitation once the credentials are extracted.",
  "technicalDetails": "The root cause of this vulnerability is the insecure practice of embedding sensitive API keys and secrets directly into the application's source code or compiled binary artifacts. In the case of the Joyland AI application, the credentials required to authenticate with the GeTui REST API are statically stored. Because these credentials are an integral part of the application package, they are easily accessible through basic static analysis and reverse engineering techniques, such as string extraction, decompilation, or binary inspection.\nThe attack flow begins with an adversary acquiring the Joyland AI application package (e.g., APK or IPA). Using static analysis tools like strings, grep, or decompilers such as Jadx or Ghidra, the attacker identifies the GeTui AppID, AppKey, and AppSecret strings stored in the application's resources or compiled classes. Once these credentials are recovered, the attacker no longer requires the application itself; they can interact directly with the GeTui REST API endpoints via standard HTTP requests.\nBy constructing specially crafted POST requests directed at the GeTui API servers, the attacker authenticates as the legitimate Joyland AI service. The API grants the attacker full administrative access to the push notification backend. The attacker can then utilize the GeTui API's targeting parameters to broadcast arbitrary messages to specific device tokens (Alias or CID) or perform a global push notification to every registered application user. The payload behavior is limited only by the features supported by the GeTui API, which typically includes the definition of notification titles, body text, deeplinks, and custom data payloads.\nThe post-exploitation impact includes the successful delivery of fraudulent notifications to end-users. An attacker can impersonate the application service to solicit credentials, distribute malware, or disrupt the user experience. Because the requests originate from the legitimate GeTui infrastructure, these notifications are treated as trusted communication by the mobile operating system, making it highly effective for social engineering. This flaw represents a total failure of credential management, granting an unauthorized third party full control over the application's outbound notification subsystem without the need for additional authentication or elevated privileges beyond the hard-coded tokens themselves."
}
CVE-2026-102666: Joyland AI Hard-Coded Credentials (MEDIUM Severity, CVSS: 6.5) | Sceawere