Description
The Mira cloud authentication endpoints do not enforce per-account rate limiting, per-IP throttling, or account lockout after repeated failed login attempts. An attacker can use brute-force methods to obtain gain access to user accounts.
Published: 2026-08-11
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability allows attackers to brute‑force user accounts through the Mira cloud authentication endpoints because rate limiting, per‑IP throttling, and account lockout are not enforced. This flaw, classified as CWE‑307, enables an adversary to obtain unauthorized access, potentially exposing sensitive health data or allowing control of the device.

Affected Systems

The flaw affects the Mira Android app and the Mira firmware device from Quanovate Tech Inc. (operating as Mira / Mira Care). All versions prior to the latest releases listed—iOS v3.5.18, Android v4.5.18, and firmware v01.07.01.53—are vulnerable; newer releases contain the fix.

Risk and Exploitability

The CVSS score of 6.9 signals moderate severity. The EPSS score is below 1%, indicating a low likelihood of current exploitation, and the vulnerability is not yet listed in the CISA KEV catalog. However, the attack vector is inferred to be remote access to the authentication service over the internet, and a determined attacker could exploit the lack of rate limiting to compromise accounts.

Generated by OpenCVE AI on August 12, 2026 at 19:23 UTC.

Remediation

Vendor Solution

Users should update the Mira app to the latest version iOS v3.5.18 / Android v4.5.18. Firmware v01.07.01.53 is updated via the app when the device is connected. No additional action is required.


OpenCVE Recommended Actions

  • Install the latest Mira Android app version 4.5.18 (or iOS 3.5.18) on all devices.
  • Update the Mira device firmware to v01.07.01.53 via the app when the device is connected.
  • Monitor account activity for repeated failed login attempts and enforce stronger controls such as complex passwords or multi‑factor authentication if available.

Generated by OpenCVE AI on August 12, 2026 at 19:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Quanovate Tech
Quanovate Tech mira Android App
Quanovate Tech mira Firmware
Vendors & Products Quanovate Tech
Quanovate Tech mira Android App
Quanovate Tech mira Firmware

Wed, 12 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 11 Aug 2026 21:30:00 +0000

Type Values Removed Values Added
Description The Mira cloud authentication endpoints do not enforce per-account rate limiting, per-IP throttling, or account lockout after repeated failed login attempts. An attacker can use brute-force methods to obtain gain access to user accounts.
Title Mira Hormone Monitor, Mira Android App Improper restriction of excessive authentication attempts
Weaknesses CWE-307
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Quanovate Tech Mira Android App Mira Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2026-08-12T12:55:57.030Z

Reserved: 2026-08-03T16:54:56.488Z

Link: CVE-2026-66340

cve-icon Vulnrichment

Updated: 2026-08-12T12:55:52.303Z

cve-icon NVD

Status : Received

Published: 2026-08-11T22:18:53.070

Modified: 2026-08-12T14:18:32.837

Link: CVE-2026-66340

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T09:49:05Z

Weaknesses
  • CWE-307

    Improper Restriction of Excessive Authentication Attempts