No analysis available yet.
Vendor Solution
Users should update the Mira app to the latest version iOS v3.5.18 / Android v4.5.18. Firmware v01.07.01.53 is updated via the app when the device is connected. No additional action is required.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 11 Aug 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Mira cloud API accepts the firmware version reported by the companion app as authoritative for a given device, without independently attesting the version from the device itself. An authenticated attacker could submit arbitrary firmware version strings for their own device, allowing them to evade vendor-side vulnerable-fleet analytics, suppress security update prompts to the user, and misrepresent patch-adoption metrics. | |
| Title | Mira Hormone Monitor, Mira Android App Reliance on untrusted inputs in a security decision | |
| Weaknesses | CWE-807 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2026-08-11T21:15:13.291Z
Reserved: 2026-08-03T16:54:56.490Z
Link: CVE-2026-64934
No data.
Status : Received
Published: 2026-08-11T22:18:41.897
Modified: 2026-08-11T22:18:41.897
Link: CVE-2026-64934
No data.
OpenCVE Enrichment
No data.
-
CWE-807
Reliance on Untrusted Inputs in a Security Decision