---
id: CVE-2026-103098
title: "Transmission of a sensitive key in the URL\nover an unencrypted HTTP connection.\_ The\nrequest is sent over HTTP rather than HTTPS, meaning the key is transmitted in\nplaintext across the network"
summary: "Transmission of a sensitive key in the URL\nover an unencrypted HTTP connection.\_ The\nrequest is sent over HTTP rather than HTTPS, meaning the key is transmitted in\nplaintext across the network. An attacker with the ability to monitor net…"
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-319
vendor: GeoVision Inc.
product: tw.com.geovision.gveye
affected:
  - tw.com.geovision.gveye V3.6.0
published: '2026-10-02'
updated: '2026-10-02'
sourceUpdated: '2026-10-02T01:16:43.193'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-103098'
references:
  - url: 'https://www.geovision.com.tw/cyber_security.php'
    label: 0df08a0e-a200-4957-9bb0-084f562506f9
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-02T01:05:54.738Z'
---

## Overview

Transmission of a sensitive key in the URL
over an unencrypted HTTP connection.  The
request is sent over HTTP rather than HTTPS, meaning the key is transmitted in
plaintext across the network. An attacker with the ability to monitor network
traffic could intercept the request and obtain the key

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
