CVE-2026-103098
Received Received - Intake

Sensitive Key Exposure via HTTP Transmission

Vulnerability report for CVE-2026-103098, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-02

Last updated on: 2026-10-02

Assigner: GV

Description

Transmission of a sensitive key in the URL over an unencrypted HTTP connection.Β  The request is sent over HTTP rather than HTTPS, meaning the key is transmitted in plaintext across the network. An attacker with the ability to monitor network traffic could intercept the request and obtain the key

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-02
Last Modified
2026-10-02
Generated
2026-10-02
AI Q&A
2026-10-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-319 The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves transmitting a sensitive key in the URL over an unencrypted HTTP connection. The request is sent via HTTP instead of HTTPS, exposing the key in plaintext across the network. Attackers monitoring network traffic could intercept and obtain the key.

Detection Guidance

To detect this vulnerability, monitor network traffic for HTTP requests containing sensitive keys in URLs. Use tools like tcpdump or Wireshark to capture and inspect packets for plaintext transmission of keys. Check web server logs for HTTP (not HTTPS) requests with key parameters.

Impact Analysis

An attacker could intercept the sensitive key, leading to unauthorized access to systems or data protected by that key. This could result in data breaches, account takeovers, or further exploitation of connected services.

Compliance Impact

This vulnerability likely violates requirements for secure data transmission in GDPR and HIPAA. GDPR mandates encryption for personal data, while HIPAA requires protection of sensitive health information. Non-compliance could result in legal penalties and reputational damage.

Mitigation Strategies

Ensure all sensitive data transmissions use HTTPS instead of HTTP to encrypt traffic. Inspect application code and configurations to identify any instances where keys or sensitive data are sent via unencrypted connections. Update or modify systems to enforce HTTPS for all relevant endpoints.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-103098. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart