rootpwn

high · CVSS v3 7.5

CVE-2026-103097

CVE-2026-103097 exposes a hardcoded API key in an Android application, allowing attackers to extract the key via reverse engineering. This e

Overview

CVE-2026-103097 exposes a hardcoded API key in an Android application, allowing attackers to extract the key via reverse engineering. This enables unauthorized use of the API, potentially compromising user data and services. The vulnerability is high severity with a CVSS score of 7.5.

Description

An API key is hardcoded and retrievable from the application package. Since Android applications can be reverse engineered, embedding sensitive API credentials directly in the client application may allow unauthorized users to extract and misuse the key.

Impact

The confidentiality of the API key is compromised, enabling attackers to access protected resources. Integrity may be affected if the key is used to perform unauthorized actions. Availability could be impacted if the API is abused, leading to rate limiting or service disruption. Defenders must protect users and services from credential misuse.

Remediation

Remove the hardcoded key from the client bundle and store it securely on the server side. Use Android Keystore or secure server-side token exchange to provide temporary tokens. Rotate the compromised key immediately and update the application. Monitor for anomalous API usage and enforce rate limiting.

Risk context

High severity (CVSS 7.5) indicates significant risk. No EPSS data available, but the vulnerability is actionable and requires prompt remediation.

Affected products

  • Android Application
  • Mobile App

Scores

Severity
high
CVSS v2
7.8
CVSS v3
7.5
CVSS v4
—
EPSS
—

hardcoded-credentials android api-key client-side confidentiality credential-exposure

← All CVEs