Description
The Joyland AI app accepts any TLS certificates from any server without validation.
Published: 2026-10-01
Score: 6.9 Medium
EPSS: n/a
KEV: No
Impact: Man-in-the-Middle via unvalidated TLS certificates
Action: Patch
AI Analysis

Impact

The Joyland AI application accepts TLS certificates presented by any server without performing validation, allowing an attacker to present a self‑signed or otherwise fraudulent certificate and establish a trusted connection. This flaw does not enable arbitrary code execution, but it permits an attacker to intercept or alter data transmitted between the application and a remote server, compromising confidentiality and potentially integrity. The weakness is identified as CWE‑295, illustrating improper handling of certificate trust.

Affected Systems

The affected product is Joyland AI, released by Joyland. Specific version information is not listed, so all current releases are potentially impacted until a fix that enforces certificate validation is applied.

Risk and Exploitability

With a CVSS base score of 6.9 the vulnerability is considered moderate and could be exploited by any adversary who can direct the application to connect to a server under their control. Because the EPSS score is not available and the issue is not listed in the CISA KEV catalog, the likelihood of widespread exploitation remains uncertain, but the accidental use of an untrusted server or a malicious internal actor could exploit the flaw in a production environment.

Generated by OpenCVE AI on October 1, 2026 at 21:22 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Joyland AI to a version that enforces TLS certificate validation.
  • Configure the application to reject self‑signed or untrusted certificates in its TLS handshake logic.
  • Verify that any reverse proxies or load balancers terminate TLS with a valid, trusted certificate before forwarding traffic to Joyland AI.

Generated by OpenCVE AI on October 1, 2026 at 21:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 20:00:00 +0000

Type Values Removed Values Added
Description The Joyland AI app accepts any TLS certificates from any server without validation.
Title Joyland AI accepts TLS certificates without validation
Weaknesses CWE-295
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: cisa-cg

Published:

Updated: 2026-10-01T19:42:45.753Z

Reserved: 2026-09-29T16:07:17.878Z

Link: CVE-2026-102668

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-10-01T20:17:21.890

Modified: 2026-10-01T20:31:38.333

Link: CVE-2026-102668

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T21:30:13Z

Weaknesses
  • CWE-295

    Improper Certificate Validation