CVE-2026-102666: Joyland AI hard-coded credentials for push notifications
Published Oct 1, 2026
·Updated
The Joyland AI app contains hard-coded credentials for the GeTui push notification service, allowing an attacker to access the GeTui REST API and send push notifications containing arbitrary content to any user, group of users, or all users of the app at once.
Affected Software
1 affected component
Joyland AI Joyland AI app
Event History
Oct 1, 2026
CVE Published
via MITRE·07:41 PM
Data Sourced
via MITRE·07:41 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
An attacker does not need prior privileges or user interaction. The exposed GeTui credentials can be used to access the GeTui REST API.
2
What could an attacker do with the exposed credentials?
They could send push notifications with arbitrary content to any individual user, selected groups of users, or all users of the app at once.
3
Is the impact limited to a specific notification audience?
No. The available credentials allow notification delivery at individual, group, and app-wide scope.