{"api_version":"1","generated_at":"2026-10-02T02:20:54+00:00","cve":"CVE-2026-103097","urls":{"html":"https://cve.report/CVE-2026-103097","api":"https://cve.report/api/cve/CVE-2026-103097.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-103097","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-103097"},"summary":{"title":"GV-Eye Relay Payment API Key Vulnerability","description":"An API key is\nhardcoded and retrievable from the application package. Since Android\napplications can be reverse engineered, embedding sensitive API credentials\ndirectly in the client application may allow unauthorized users to extract and\nmisuse the key.","state":"PUBLISHED","assigner":"GV","published_at":"2026-10-02 01:16:43","updated_at":"2026-10-02 01:16:43"},"problem_types":["CWE-312","CWE-540","CWE-798","CWE-798 CWE-798: Use of Hard-coded Credentials","CWE-540 CWE-540 Inclusion of sensitive information in source code","CWE-312 CWE-312 Cleartext storage of sensitive information"],"metrics":[{"version":"3.1","source":"0df08a0e-a200-4957-9bb0-084f562506f9","type":"Secondary","score":"7.5","severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"}},{"version":"3.1","source":"CNA","type":"CVSS","score":"7.5","severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","data":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","version":"3.1"}}],"references":[{"url":"https://www.geovision.com.tw/cyber_security.php","name":"https://www.geovision.com.tw/cyber_security.php","refsource":"0df08a0e-a200-4957-9bb0-084f562506f9","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-103097","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-103097","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"GeoVision Inc.","product":"GV-Eye","version":"affected V3.6.0","platforms":["Android"]},{"source":"CNA","vendor":"GeoVision Inc.","product":"GV-Eye","version":"unaffected V3.7.2","platforms":["Android"]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[{"source":"CNA","value":"Lloyd Lexter Gealon","lang":"en"}],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","packageName":"tw.com.geovision.gveye","platforms":["Android"],"product":"GV-Eye","vendor":"GeoVision Inc.","versions":[{"status":"affected","version":"V3.6.0"},{"status":"unaffected","version":"V3.7.2"}]}],"cpeApplicability":[{"nodes":[{"cpeMatch":[{"criteria":"cpe:2.3:a:geovision_inc.:gv-eye:v3.6.0:*:android:*:*:*:*:*","vulnerable":true},{"criteria":"cpe:2.3:a:geovision_inc.:gv-eye:v3.7.2:*:android:*:*:*:*:*","vulnerable":false}],"negate":false,"operator":"OR"}],"operator":"OR"}],"credits":[{"lang":"en","type":"finder","value":"Lloyd Lexter Gealon"}],"datePublic":"2026-09-30T02:15:00.000Z","descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p>An API key is\nhardcoded and retrievable from the application package. Since Android\napplications can be reverse engineered, embedding sensitive API credentials\ndirectly in the client application may allow unauthorized users to extract and\nmisuse the key.</p>"}],"value":"An API key is\nhardcoded and retrievable from the application package. Since Android\napplications can be reverse engineered, embedding sensitive API credentials\ndirectly in the client application may allow unauthorized users to extract and\nmisuse the key."}],"impacts":[{"capecId":"CAPEC-37","descriptions":[{"lang":"en","value":"CAPEC-37 Retrieve Embedded Sensitive Data"}]},{"capecId":"CAPEC-188","descriptions":[{"lang":"en","value":"CAPEC-188 Reverse Engineering"}]},{"capecId":"CAPEC-618","descriptions":[{"lang":"en","value":"CAPEC-618 Cellular Broadcast Message Request"}]}],"metrics":[{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","version":"3.1"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]}],"problemTypes":[{"descriptions":[{"cweId":"CWE-798","description":"CWE-798: Use of Hard-coded Credentials","lang":"en","type":"CWE"}]},{"descriptions":[{"cweId":"CWE-540","description":"CWE-540 Inclusion of sensitive information in source code","lang":"en","type":"CWE"}]},{"descriptions":[{"cweId":"CWE-312","description":"CWE-312 Cleartext storage of sensitive information","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-10-02T00:14:46.555Z","orgId":"0df08a0e-a200-4957-9bb0-084f562506f9","shortName":"GV"},"references":[{"tags":["vendor-advisory"],"url":"https://www.geovision.com.tw/cyber_security.php"}],"source":{"discovery":"UNKNOWN"},"title":"GV-Eye Relay Payment API Key Vulnerability","x_generator":{"engine":"Vulnogram 1.0.5"}}},"cveMetadata":{"assignerOrgId":"0df08a0e-a200-4957-9bb0-084f562506f9","assignerShortName":"GV","cveId":"CVE-2026-103097","datePublished":"2026-10-02T00:14:46.555Z","dateReserved":"2026-09-30T02:10:01.788Z","dateUpdated":"2026-10-02T00:14:46.555Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-10-02 01:16:43","lastModifiedDate":"2026-10-02 01:16:43","problem_types":["CWE-312","CWE-540","CWE-798","CWE-798 CWE-798: Use of Hard-coded Credentials","CWE-540 CWE-540 Inclusion of sensitive information in source code","CWE-312 CWE-312 Cleartext storage of sensitive information"],"metrics":{"cvssMetricV31":[{"source":"0df08a0e-a200-4957-9bb0-084f562506f9","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":3.6}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"103097","Ordinal":"1","Title":"GV-Eye Relay Payment API Key Vulnerability","CVE":"CVE-2026-103097","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"103097","Ordinal":"1","NoteData":"An API key is\nhardcoded and retrievable from the application package. Since Android\napplications can be reverse engineered, embedding sensitive API credentials\ndirectly in the client application may allow unauthorized users to extract and\nmisuse the key.","Type":"Description","Title":"GV-Eye Relay Payment API Key Vulnerability"}]}}}