Description
API
key is hardcoded and retrievable from the application package. Since Android
applications can be reverse engineered, embedding sensitive API credentials
directly in the client application may allow unauthorized users to extract and
misuse the key.
Published: 2026-10-02
Score: 7.5 High
EPSS: n/a
KEV: No
Impact: Unauthorized API Access
Action: Immediate Patch
AI Analysis

Impact

GV‑Eye, a proprietary Android application developed by GeoVision Inc., contains a fixed API key that is embedded directly in the application bundle. This key can be extracted by anyone with the APK through reverse engineering techniques, exposing it for misuse by unauthorized users. The exposed key can be used to call GV‑Eye’s backend services, potentially allowing attackers to access or manipulate data and resources that should be protected, thereby compromising confidentiality and integrity. The weakness corresponds to CWE‑312, CWE‑540, and CWE‑798, all of which indicate insecure storage and use of credentials.

Affected Systems

GeoVision Inc. GV‑Eye version 3.6.0 and 3.7.2 for Android. The vulnerability exists in applications distributed for the Android platform.

Risk and Exploitability

Because the key is embedded, an attacker only needs to obtain the APK, which is readily available to anyone who installs the app. Reverse engineering is safe and allowed, removes the need for network interaction or special privileges, making exploitation straightforward. The CVSS score of 7.5 classifies it as a high severity vulnerability, and while an EPSS score is not provided, the ease of extraction suggests a non‑negligible probability of exploitation. The vulnerability is currently not listed in the CISA KEV catalog, but the exposure could be considerable for users relying on the API functionality.

Generated by OpenCVE AI on October 2, 2026 at 02:25 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade GeoVision’s GV‑Eye Android client to the latest official release that eliminates embedded API keys.
  • If an update is not yet available, coordinate with GeoVision to revoke the compromised key and issue a new, limited‑scope key.
  • Implement server‑side controls such as IP whitelisting, rate limiting, or API key expiration to reduce the impact of any extracted key.

Generated by OpenCVE AI on October 2, 2026 at 02:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 01:00:00 +0000

Type Values Removed Values Added
Description API key is hardcoded and retrievable from the application package. Since Android applications can be reverse engineered, embedding sensitive API credentials directly in the client application may allow unauthorized users to extract and misuse the key.
Title GV-Eye Hardcoded API Key Vulnerability
First Time appeared Geovision Inc.
Geovision Inc. gv-eye
Weaknesses CWE-312
CWE-540
CWE-798
CPEs cpe:2.3:a:geovision_inc.:gv-eye:v3.6.0:*:android:*:*:*:*:*
cpe:2.3:a:geovision_inc.:gv-eye:v3.7.2:*:android:*:*:*:*:*
Vendors & Products Geovision Inc.
Geovision Inc. gv-eye
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Geovision Inc. Gv-eye
cve-icon MITRE

Status: PUBLISHED

Assigner: GV

Published:

Updated: 2026-10-02T00:14:08.149Z

Reserved: 2026-09-30T02:10:01.725Z

Link: CVE-2026-103096

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-02T01:16:42.930

Modified: 2026-10-02T01:16:42.930

Link: CVE-2026-103096

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T02:30:18Z

Weaknesses
  • CWE-312

    Cleartext Storage of Sensitive Information

  • CWE-540

    Inclusion of Sensitive Information in Source Code

  • CWE-798

    Use of Hard-coded Credentials