CVE-2026-102666
Deferred Deferred - Pending Action

Hard-Coded Credentials in Joyland AI App

Vulnerability report for CVE-2026-102666, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-01

Last updated on: 2026-10-01

Assigner: Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government

Description

The Joyland AI app contains hard-coded credentials for the GeTui push notification service, allowing an attacker to access the GeTui REST API and send push notifications containing arbitrary content to any user, group of users, or all users of the app at once.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-01
Last Modified
2026-10-01
Generated
2026-10-02
AI Q&A
2026-10-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-798 The product contains hard-coded credentials, such as a password or cryptographic key.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The Joyland AI app has hard-coded credentials for the GeTui push notification service. This allows attackers to access the GeTui REST API and send push notifications with arbitrary content to any user or group of users of the app.

Detection Guidance

To detect hard-coded credentials in the Joyland AI app, inspect app binaries or configuration files for embedded GeTui push notification service credentials. Search for strings like 'GeTui', 'push notification', or API keys in app files or network traffic logs.

Impact Analysis

Attackers could send fake or malicious push notifications to users, potentially tricking them into revealing sensitive information or installing malware. This could lead to phishing attacks or unauthorized access to user data.

Compliance Impact

This vulnerability could violate GDPR by exposing user data through unauthorized notifications or enabling phishing attacks. For HIPAA, it may risk protected health information if notifications are manipulated to extract or alter data.

Mitigation Strategies

Remove or replace any hard-coded credentials in the Joyland AI app that are used for the GeTui push notification service. Update the app to use secure credential storage methods instead.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-102666. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart