CVE-2026-102668: Joyland AI accepts TLS certificates without validation
Published Oct 1, 2026
·Updated
The Joyland AI app accepts any TLS certificates from any server without validation.
Affected Software
1 affected component
Joyland AI Joyland AI
Event History
Oct 1, 2026
CVE Published
via MITRE·07:42 PM
Data Sourced
via MITRE·07:42 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What would an attacker need to exploit this issue?
An attacker would need to position themselves between the Joyland AI app and a server it connects to, or otherwise control a network path or server endpoint. Because the app accepts any TLS certificate, certificate-based identity checks do not prevent interception.
2
What is the security impact of successful exploitation?
The reported impact is limited to integrity. An attacker able to intercept the connection could modify traffic without a certificate validation failure from the app.
3
Can this be exploited without user interaction or prior authentication?
The CVSS vector indicates no privileges and no user interaction are required. The attack vector is network-based and has low attack complexity.