high · CVSS v3 7.5
CVE-2026-103097
CVE-2026-103097 exposes a hardcoded API key in an Android application, allowing attackers to extract the key via reverse engineering. This e
Overview
CVE-2026-103097 exposes a hardcoded API key in an Android application, allowing attackers to extract the key via reverse engineering. This enables unauthorized use of the API, potentially compromising user data and services. The vulnerability is high severity with a CVSS score of 7.5.
Description
An API key is hardcoded and retrievable from the application package. Since Android applications can be reverse engineered, embedding sensitive API credentials directly in the client application may allow unauthorized users to extract and misuse the key.
Impact
The confidentiality of the API key is compromised, enabling attackers to access protected resources. Integrity may be affected if the key is used to perform unauthorized actions. Availability could be impacted if the API is abused, leading to rate limiting or service disruption. Defenders must protect users and services from credential misuse.
Remediation
Remove the hardcoded key from the client bundle and store it securely on the server side. Use Android Keystore or secure server-side token exchange to provide temporary tokens. Rotate the compromised key immediately and update the application. Monitor for anomalous API usage and enforce rate limiting.
Risk context
High severity (CVSS 7.5) indicates significant risk. No EPSS data available, but the vulnerability is actionable and requires prompt remediation.
Affected products
- Android Application
- Mobile App
Scores
- Severity
- high
- CVSS v2
- 7.8
- CVSS v3
- 7.5
- CVSS v4
- —
- EPSS
- —