CVE WATCH / VULNERABILITY DETAIL
CVE-2026-103097
HIGHCVSS 7.5NVD feed
Published 2 October 2026 · tracked since 2 October 2026
Description
An API key is hardcoded and retrievable from the application package. Since Android applications can be reverse engineered, embedding sensitive API credentials directly in the client application may allow unauthorized users to extract and misuse the key.
References
- NVD — National Vulnerability Database
- CVE.org record (MITRE)
- CISA Known Exploited Vulnerabilities catalog
Latest tracked vulnerabilities
- CVE-2026-104052 MEDIUM 6.3
- CVE-2026-104053 MEDIUM 6.3
- CVE-2026-103096 HIGH 7.5
- CVE-2026-103764 CRITICAL 9.8
- CVE-2026-103766 HIGH 7.2
- CVE-2026-103760 MEDIUM 5.9
- CVE-2026-104002 MEDIUM 5.3
- CVE-2026-104356 MEDIUM 5.9
- CVE-2026-104182 MEDIUM 6.2
- CVE-2026-104183 MEDIUM 5.1