CVE-2026-103097
Received
Received - Intake
Hard-Coded API Key in Android Application
Vulnerability report for CVE-2026-103097, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-10-02
Last updated on: 2026-10-02
Assigner: GV
Description
Description
An API key is
hardcoded and retrievable from the application package. Since Android
applications can be reverse engineered, embedding sensitive API credentials
directly in the client application may allow unauthorized users to extract and
misuse the key.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
Currently, no data is known.
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-798 | The product contains hard-coded credentials, such as a password or cryptographic key. |
| CWE-540 | Source code on a web server or repository often contains sensitive information and should generally not be accessible to users. |
| CWE-312 | The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere. |