CVE-2026-103097: GV-Eye Relay Payment API Key Vulnerability
An API key is hardcoded and retrievable from the application package. Since Android applications can be reverse engineered, embedding sensitive API credentials directly in the client application may allow unauthorized users to extract and misuse the key.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
Any party able to obtain the GV-Eye Relay Android application package may be able to reverse engineer it and extract the embedded API key. No authentication, user interaction, or other privileges are indicated as required.
What is the likely impact of a recovered key?
The available information identifies possible unauthorized misuse of the API key and rates confidentiality impact as high. It does not specify which API functions or data are accessible with the key.
How can an organization determine whether it is affected?
Organizations using GeoVision GV-Eye Relay should treat the application package as the exposure point and assess whether the embedded key is accepted by the associated payment API. The provided information does not identify affected versions or a fixed release.