---
id: CVE-2026-103097
title: |-
  An API key is
  hardcoded and retrievable from the application package
summary: |-
  An API key is
  hardcoded and retrievable from the application package. Since Android
  applications can be reverse engineered, embedding sensitive API credentials
  directly in the client application may allow unauthorized users to extract an…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-312
  - CWE-540
  - CWE-798
vendor: GeoVision Inc.
product: tw.com.geovision.gveye
affected:
  - tw.com.geovision.gveye V3.6.0
published: '2026-10-02'
updated: '2026-10-02'
sourceUpdated: '2026-10-02T01:16:43.070'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-103097'
references:
  - url: 'https://www.geovision.com.tw/cyber_security.php'
    label: 0df08a0e-a200-4957-9bb0-084f562506f9
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-02T01:05:54.740Z'
---

## Overview

An API key is
hardcoded and retrievable from the application package. Since Android
applications can be reverse engineered, embedding sensitive API credentials
directly in the client application may allow unauthorized users to extract and
misuse the key.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
