{"id":"CVE-2026-103098","title":"Transmission of a sensitive key in the URL\nover an unencrypted HTTP connection.  The\nrequest is sent over HTTP rather than HTTPS, meaning the key is transmitted in\nplaintext across the network","summary":"Transmission of a sensitive key in the URL\nover an unencrypted HTTP connection.  The\nrequest is sent over HTTP rather than HTTPS, meaning the key is transmitted in\nplaintext across the network. An attacker with the ability to monitor net…","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","cwe":["CWE-319"],"vendor":"GeoVision Inc.","product":"tw.com.geovision.gveye","affected":["tw.com.geovision.gveye V3.6.0"],"published":"2026-10-02","updated":"2026-10-02","sourceUpdated":"2026-10-02T01:16:43.193","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-103098","references":[{"url":"https://www.geovision.com.tw/cyber_security.php","label":"0df08a0e-a200-4957-9bb0-084f562506f9"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-10-02T01:05:54.738Z","slug":"CVE-2026-103098","body":"## Overview\n\nTransmission of a sensitive key in the URL\nover an unencrypted HTTP connection.  The\nrequest is sent over HTTP rather than HTTPS, meaning the key is transmitted in\nplaintext across the network. An attacker with the ability to monitor network\ntraffic could intercept the request and obtain the key\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}