OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-103096

HIGH · CVSS 7.5 EPSS 0.15%

Source: NVD + CISA KEV + EPSS · Published 2026-10-02 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

Android applications are vulnerable due to the hardcoding of sensitive API keys within the application package, making them retrievable through reverse engineering. This flaw could lead to unauthorized access and misuse of the API, potentially compromising sensitive data and services. Developers and organizations utilizing affected Android applications should prioritize addressing this vulnerability to mitigate the risk of credential exposure.

CVE
CVE-2026-103096
Severity
HIGH
CVSS
7.5
EPSS
0.15%
Android

Original NVD Description

API key is hardcoded and retrievable from the application package. Since Android applications can be reverse engineered, embedding sensitive API credentials directly in the client application may allow unauthorized users to extract and misuse the key.