Description
The Joyland AI app accepts invalid SSL certificates in the invisible advertisement WebView by default.
Published: 2026-10-01
Score: 6.9 Medium
EPSS: n/a
KEV: No
Impact: Man-in-the-Middle vulnerability via SSL certificate validation
Action: Apply Patch
AI Analysis

Impact

The Joyland AI application uses an invisible advertisement WebView that, by default, accepts invalid SSL certificates. This flaw permits an attacker to supply a bogus certificate, allowing interception or tampering of data transmitted in the WebView and potentially injecting malicious content or stealing information. The weakness stems from improper certificate validation, as defined by CWE-295, and could compromise confidentiality and integrity of user traffic.

Affected Systems

The affected product is Joyland AI from Joyland. No specific version range is listed, so the default configuration in the available releases is impacted. Users of the Joyland AI app should verify the build and consult the vendor for any patch information.

Risk and Exploitability

With a CVSS score of 6.9, the vulnerability is moderately severe but not critical. The EPSS score is not available and the vulnerability is not yet listed in the CISA KEV catalog, indicating no confirmed exploitation yet. The attack vector is inferred to be remote, as the problem occurs over network connections to advertisement servers; a threat actor could perform a man‑in‑the‑middle by presenting a forged certificate to the device's advertisement WebView.

Generated by OpenCVE AI on October 1, 2026 at 21:20 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Download and install the latest Joyland AI release that implements proper SSL certificate validation.
  • If an update cannot be applied immediately, block or restrict the app’s outbound connections to the advertisement servers using firewall or DNS rules, or employ a network policy that rejects connections presenting untrusted certificates.
  • Disable or remove the advertisement WebView component in the app configuration until the vendor releases a fix.

Generated by OpenCVE AI on October 1, 2026 at 21:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 20:00:00 +0000

Type Values Removed Values Added
Description The Joyland AI app accepts invalid SSL certificates in the invisible advertisement WebView by default.
Title Joyland AI WebView accepts invalid SSL certificates
Weaknesses CWE-295
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: cisa-cg

Published:

Updated: 2026-10-01T19:43:44.950Z

Reserved: 2026-09-29T16:07:47.714Z

Link: CVE-2026-102671

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-10-01T20:17:22.307

Modified: 2026-10-01T20:31:38.333

Link: CVE-2026-102671

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T21:30:13Z

Weaknesses
  • CWE-295

    Improper Certificate Validation