{"id":"CVE-2026-103097","title":"An API key is\nhardcoded and retrievable from the application package","summary":"An API key is\nhardcoded and retrievable from the application package. Since Android\napplications can be reverse engineered, embedding sensitive API credentials\ndirectly in the client application may allow unauthorized users to extract an…","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","cwe":["CWE-312","CWE-540","CWE-798"],"vendor":"GeoVision Inc.","product":"tw.com.geovision.gveye","affected":["tw.com.geovision.gveye V3.6.0"],"published":"2026-10-02","updated":"2026-10-02","sourceUpdated":"2026-10-02T01:16:43.070","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-103097","references":[{"url":"https://www.geovision.com.tw/cyber_security.php","label":"0df08a0e-a200-4957-9bb0-084f562506f9"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-10-02T01:05:54.740Z","slug":"CVE-2026-103097","body":"## Overview\n\nAn API key is\nhardcoded and retrievable from the application package. Since Android\napplications can be reverse engineered, embedding sensitive API credentials\ndirectly in the client application may allow unauthorized users to extract and\nmisuse the key.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}