Sceawere

Vulnerability Detail

CVE-2026-102670UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Joyland AI Cleartext Traffic Permitted

Vulnerability Metadata

Severity
Medium
Score / CVSS
4.3
Creation Date
1d ago
Vendor
Joyland
Product
Joyland.ai
Attack Type
CWE-319 Cleartext Transmission of Sensitive Information
Vector String
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

Joyland AI app explicitly permits cleartext HTTP traffic on Android 9+ where the default is to block it.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "4.3",
  "pubDate": "2026-10-01T20:17:22.160Z",
  "pubdate": "2026-10-01T20:17:22.160Z",
  "executiveSummary": "The Joyland AI application for Android exhibits an improper configuration of network security policies by explicitly permitting cleartext HTTP traffic on Android 9 (API level 28) and higher.\nBy default, Android 9 enforces 'android:usesCleartextTraffic=\"false\"' to protect data in transit. The application's override of this security control exposes sensitive user data to interception, modification, and injection attacks.\nThe vulnerability affects Joyland AI on Android platforms where modern security defaults are bypassed. The risk implication is significant, as it enables unauthorized parties to perform Man-in-the-Middle (MitM) attacks.\nAn attacker positioned on the same network path, such as an unsecured public Wi-Fi or a compromised gateway, can capture or manipulate application traffic without the need for sophisticated decryption methods, as the traffic is transmitted in an unencrypted format.",
  "technicalDetails": "The root cause of this vulnerability is the explicit configuration within the Android application's Network Security Configuration or the AndroidManifest.xml file, which overrides the platform's default 'usesCleartextTraffic' setting.\nStarting with Android 9 (API level 28), the Android platform introduced a strict security requirement that disables cleartext HTTP communication by default to prevent accidental data exposure. By configuring the application to explicitly permit cleartext traffic, Joyland AI degrades the security posture of the application by allowing unencrypted HTTP connections to transit over the network.\nThe exploitation flow begins with the attacker positioning themselves as a Man-in-the-Middle between the Joyland AI application and the backend infrastructure. This is typically achieved via ARP spoofing, DNS poisoning, or the use of rogue Wi-Fi access points. Once the attacker intercepts the traffic, the lack of TLS/SSL encryption allows them to read, modify, or inject data into the application's network stream in real-time.\nSince the traffic is transmitted in plaintext, the attacker does not need to perform complex SSL/TLS stripping or certificate pinning bypasses. The application will accept the cleartext connection without generating security warnings, facilitating seamless data theft. The exposed information could include authentication tokens, session identifiers, sensitive user data, or application-specific PII (Personally Identifiable Information).\nThis vulnerability persists regardless of the application's authentication requirements, as the transport layer itself is compromised. Even if the application employs authentication, the credentials or tokens passed over the wire are sent in the clear, allowing an attacker to hijack active user sessions. Post-exploitation, the attacker may perform unauthorized actions on behalf of the user or gain persistent access to user accounts depending on the application's logic. This configuration essentially invalidates the confidentiality and integrity guarantees provided by modern Android network security stacks."
}
CVE-2026-102670: Joyland AI Cleartext Traffic Permitted (MEDIUM Severity, CVSS: 4.3) | Sceawere