---
id: CVE-2026-103096
title: |-
  API
  key is hardcoded and retrievable from the application package
summary: |-
  API
  key is hardcoded and retrievable from the application package. Since Android
  applications can be reverse engineered, embedding sensitive API credentials
  directly in the client application may allow unauthorized users to extract and
  m…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-312
  - CWE-540
  - CWE-798
vendor: GeoVision Inc.
product: tw.com.geovision.gveye
affected:
  - tw.com.geovision.gveye V3.6.0
published: '2026-10-02'
updated: '2026-10-02'
sourceUpdated: '2026-10-02T01:16:42.930'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-103096'
references:
  - url: 'https://www.geovision.com.tw/cyber_security.php'
    label: 0df08a0e-a200-4957-9bb0-084f562506f9
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-02T01:05:54.740Z'
---

## Overview

API
key is hardcoded and retrievable from the application package. Since Android
applications can be reverse engineered, embedding sensitive API credentials
directly in the client application may allow unauthorized users to extract and
misuse the key.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
