CVE-2026-103096: GV-Eye Hardcoded API Key Vulnerability
API key is hardcoded and retrievable from the application package. Since Android applications can be reverse engineered, embedding sensitive API credentials directly in the client application may allow unauthorized users to extract and misuse the key.
Affected Software
Event History
Frequently Asked Questions
What does an attacker need to exploit this issue?
An attacker needs access to the GV-Eye Android application package so they can reverse engineer it and retrieve the embedded API key. No authentication or user interaction is indicated by the supplied severity vector.
Who is exposed to misuse of the key?
Any party able to obtain and reverse engineer the GV-Eye application package could potentially extract the key and use it without authorization. The available information does not identify which backend API functions or accounts are accessible with the key.
How can defenders determine whether they are affected?
Review the GV-Eye Android application package for API credentials embedded in code, resources, or configuration files. The provided information does not include affected versions or a method for identifying a specific vulnerable build.