OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-102667

HIGH · CVSS 8.3 EPSS 0.19%

Source: NVD + CISA KEV + EPSS · Published 2026-10-01 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

The Joyland AI app is vulnerable due to its inadequate input validation, allowing attackers with shared network access to inject JavaScript into WebView content. This exploitation can lead to unauthorized access to sensitive data, including the clipboard and app-internal storage, and if prior permissions have been granted, attackers could gain control over the entire file system, camera, microphone, and GPS. Organizations using this app should prioritize addressing this vulnerability to mitigate potential data breaches and unauthorized access.

CVE
CVE-2026-102667
Severity
HIGH
CVSS
8.3
EPSS
0.19%
Java

Original NVD Description

Joyland AI app allows an attacker with shared network access to inject JavaScript into content loaded in WebView. Without user-granted permissions, an attacker could access the clipboard, make arbitrary HTTP requests via the Weex 'stream' module, or access app-internal storage. If the installed app has been granted permissions previously, the attacker can access the entire file system, camera, microphone, and GPS tracking.