Security Vulnerability in Joyland AI App Exposing GeTui Notification Service
CVE-2026-102666

6.9MEDIUM

Key Information:

Vendor

Joyland

Vendor
CVE Published:
1 October 2026

What is CVE-2026-102666?

The Joyland AI app is susceptible to exploitation due to hard-coded credentials for the GeTui push notification service. This vulnerability enables an attacker to access the GeTui REST API, which can result in unauthorized push notifications being sent to any, some, or all users of the app. Such unauthorized access could lead to potential spam attacks or the dissemination of harmful content, thereby compromising user trust and safety.

Affected Version(s)

Joyland.ai *

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Vincent C., CodeVispera
.