Sceawere
Vulnerability Detail
CVE-2026-102666UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Joyland AI Hard-Coded Credentials
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6.5
- Creation Date
- 1d ago
- Vendor
- Joyland
- Product
- Joyland.ai
- Attack Type
- CWE-798 Use of Hard-coded Credentials
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
The Joyland AI app contains hard-coded credentials for the GeTui push notification service, allowing an attacker to access the GeTui REST API and send push notifications containing arbitrary content to any user, group of users, or all users of the app at once.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.5",
"pubDate": "2026-10-01T20:17:21.610Z",
"pubdate": "2026-10-01T20:17:21.610Z",
"executiveSummary": "The Joyland AI application contains hard-coded credentials for the GeTui push notification service, introducing a significant security vulnerability. This flaw involves the embedding of sensitive API authentication tokens directly within the application binary, which allows unauthorized access to the GeTui REST API infrastructure. By leveraging these exposed credentials, an attacker can bypass standard authentication mechanisms to interact directly with the push notification gateway associated with the application. The primary impact of this vulnerability is the ability to perform unauthorized message injection, enabling an attacker to send arbitrary push notifications to any subset or the entire user base of the Joyland AI application. This poses severe risks, including the potential for mass phishing attacks, the dissemination of malicious links, and the delivery of misleading information to users, thereby compromising the integrity of the application's communication channel and eroding user trust in the platform's security posture. No specialized access or user interaction is required for an attacker to initiate this exploitation once the credentials are extracted.",
"technicalDetails": "The root cause of this vulnerability is the insecure practice of embedding sensitive API keys and secrets directly into the application's source code or compiled binary artifacts. In the case of the Joyland AI application, the credentials required to authenticate with the GeTui REST API are statically stored. Because these credentials are an integral part of the application package, they are easily accessible through basic static analysis and reverse engineering techniques, such as string extraction, decompilation, or binary inspection.\nThe attack flow begins with an adversary acquiring the Joyland AI application package (e.g., APK or IPA). Using static analysis tools like strings, grep, or decompilers such as Jadx or Ghidra, the attacker identifies the GeTui AppID, AppKey, and AppSecret strings stored in the application's resources or compiled classes. Once these credentials are recovered, the attacker no longer requires the application itself; they can interact directly with the GeTui REST API endpoints via standard HTTP requests.\nBy constructing specially crafted POST requests directed at the GeTui API servers, the attacker authenticates as the legitimate Joyland AI service. The API grants the attacker full administrative access to the push notification backend. The attacker can then utilize the GeTui API's targeting parameters to broadcast arbitrary messages to specific device tokens (Alias or CID) or perform a global push notification to every registered application user. The payload behavior is limited only by the features supported by the GeTui API, which typically includes the definition of notification titles, body text, deeplinks, and custom data payloads.\nThe post-exploitation impact includes the successful delivery of fraudulent notifications to end-users. An attacker can impersonate the application service to solicit credentials, distribute malware, or disrupt the user experience. Because the requests originate from the legitimate GeTui infrastructure, these notifications are treated as trusted communication by the mobile operating system, making it highly effective for social engineering. This flaw represents a total failure of credential management, granting an unauthorized third party full control over the application's outbound notification subsystem without the need for additional authentication or elevated privileges beyond the hard-coded tokens themselves."
}