CVE-2026-103096
API key is hardcoded and retrievable from the application package. Since Android applications can be reverse engineered, embedding sensitive
CVSS
7.5
High
EPSS
0.2%
p4
KEV
—
Exploit Today
1
0-100
Published: Oct 2, 2026 · Last modified: Oct 2, 2026 · CWE-312 · CWE-540 · CWE-798
0.2%EPSS · 30 days0.2%
2026-10-022026-10-08
API key is hardcoded and retrievable from the application package. Since Android applications can be reverse engineered, embedding sensitive API credentials directly in the client application may allow unauthorized users to extract and misuse the key.
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-848915.9 MED—
——0IBM Guardium Data Protection 12.0, 12.1, and 12.2 could allow a remote attacker to obtain sensitive information due to use of hard-coded credentials.9hCVE-2026-102368——
——0Affected Tapo device firmware stores device-specific cryptographic material in plaintext within nonvolatile storage. An attacker with physical access to an affected device can recover this sensitive material from the firmware.
Successful exploitation of this vulnerability may result in the disclosure of device-specific cryptographic material and could, under certain conditions, increase the risk of unauthorized access to related protected information or communications.9hCVE-2026-842508.4 HIG—
——0IBM Guardium Data Protection 12.2 is vulnerable due to weak cryptographic protection and a hard-coded recovery key in the pkcrypto passkey component. A local attacker could exploit this vulnerability to recover the root password and gain root privileges.10hCVE-2026-85488—0.5%
——0Brocade ASCG before 3.5.0 has a well-known Brocade default password embedded in a script distributed to every customer. Any local authenticated user with read access to the installation path can discover this credential and perform privilege escalation on affected Open Virtual Appliance (OVA) deployments, where default configuration settings remain in place.11hCVE-2026-85422—1.0%
——0A vulnerability in Brocade ASCG version before 3.5.0 could allow an attacker to obtain a static cryptographic key hardcoded into the software binaries to secure sensitive data at rest and to protect inter-node communication protocols. An attacker who extracts this key can decrypt stored management credentials or craft forged administrative synchronization messages.11hCVE-2026-928614.0 MED1.2%
——0The Android application "Ticket Ryutsu Center" contains hard-coded credentials, which may allow an attacker to obtain an API key used by the application.10h