{"id":"CVE-2026-103096","title":"API\nkey is hardcoded and retrievable from the application package","summary":"API\nkey is hardcoded and retrievable from the application package. Since Android\napplications can be reverse engineered, embedding sensitive API credentials\ndirectly in the client application may allow unauthorized users to extract and\nm…","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","cwe":["CWE-312","CWE-540","CWE-798"],"vendor":"GeoVision Inc.","product":"tw.com.geovision.gveye","affected":["tw.com.geovision.gveye V3.6.0"],"published":"2026-10-02","updated":"2026-10-02","sourceUpdated":"2026-10-02T01:16:42.930","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-103096","references":[{"url":"https://www.geovision.com.tw/cyber_security.php","label":"0df08a0e-a200-4957-9bb0-084f562506f9"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-10-02T01:05:54.740Z","slug":"CVE-2026-103096","body":"## Overview\n\nAPI\nkey is hardcoded and retrievable from the application package. Since Android\napplications can be reverse engineered, embedding sensitive API credentials\ndirectly in the client application may allow unauthorized users to extract and\nmisuse the key.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}