CVE-2026-103096
GV-Eye Hardcoded API Key Vulnerability
CVSS Score
7.5
EPSS Score
0.0%
EPSS Percentile
0th
API key is hardcoded and retrievable from the application package. Since Android applications can be reverse engineered, embedding sensitive API credentials directly in the client application may allow unauthorized users to extract and misuse the key.
| CWE | CWE-798 CWE-540 CWE-312 |
| Vendor | geovision inc. |
| Product | gv-eye |
| Published | Oct 2, 2026 |
Stay Ahead of the Next One
Get instant alerts for geovision inc. gv-eye
Be the first to know when new high vulnerabilities affecting geovision inc. gv-eye are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None
Affected Versions
GeoVision Inc. / GV-Eye
V3.6.0
References
Credits
Lloyd Lexter Gealon