OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-103097

HIGH · CVSS 7.5 EPSS 0.15%

Source: NVD + CISA KEV + EPSS · Published 2026-10-02 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

Android applications are vulnerable due to hardcoded API keys that can be easily extracted through reverse engineering. This exposure can lead to unauthorized access and misuse of sensitive services associated with the API key, potentially compromising application security and user data. Developers and organizations deploying Android apps should prioritize addressing this vulnerability to mitigate risks associated with credential leakage.

CVE
CVE-2026-103097
Severity
HIGH
CVSS
7.5
EPSS
0.15%
Android

Original NVD Description

An API key is hardcoded and retrievable from the application package. Since Android applications can be reverse engineered, embedding sensitive API credentials directly in the client application may allow unauthorized users to extract and misuse the key.