CVE-2026-102666Medium· 6.5▾ SunlitThe Joyland AI app contains hard-coded credentials for the GeTui push notification service, allowing an attacker to access the GeTui REST API and send push notifications containing arbitrary content to any user, group of users, or all us…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 35.8 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
The Joyland AI app contains hard-coded credentials for the GeTui push notification service, allowing an attacker to access the GeTui REST API and send push notifications containing arbitrary content to any user, group of users, or all users of the app at once.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-102667High· 8.3Joyland AI app allows an attacker with shared network access to inject JavaScript into content loaded in WebView
CVE-2026-102670Medium· 4.3Joyland AI app explicitly permits cleartext HTTP traffic on Android 9+ where the default is to block it.
CVE-2026-102668Medium· 5.3The Joyland AI app accepts any TLS certificates from any server without validation.
CVE-2026-102669Medium· 5.3Joyland AI app does not verify hostnames, allowing a malicious host to connect or intercept chat messages.
CVE-2026-102671Medium· 5.3The Joyland AI app accepts invalid SSL certificates in the invisible advertisement WebView by default.
CVE-2019-6693Medium· 6.5Use of a hard-coded cryptographic key to cipher sensitive data in FortiOS configuration backup file may allow an attacker with access to the backup file to decipher the sensitive data, via knowledge of the hard-coded key