Description
The distributed Mira Android APK v4.5.15.4 allows an attacker read/write access to reproductive health profiles from internet connected hosts, which could result in forgery, deletion, or destruction of health information.
Published: 2026-08-11
Score: 9.3 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Based on the title, it is inferred that the vulnerability arises from the use of hard‑coded credentials within the Mira Android application. These credentials enable an attacker to read or modify reproductive health profiles stored on an internet‑connected host, potentially facilitating the forgery of records, deletion of data, or destruction of sensitive health information.

Affected Systems

Vulnerable assets include the Mira Android app (v4.5.15.4) and the accompanying Mira firmware. The affected vendor is Quanovate Tech Inc., operating as Mira / Mira Care. Users should upgrade to the Mira Android app version 4.5.18 and firmware version 01.07.01.53.

Risk and Exploitability

The CVSS score of 9.3 classifies this issue as critical, yet the EPSS score of <1% indicates that exploits are rare and the vulnerability is not listed in the CISA KEV catalog. The flaw can be abused by any entity that obtains or reverse‑engineers the app, making the attack vector primarily client‑side on an internet‑connected host. Successful exploitation grants complete read/write authority over personal medical data, posing significant confidentiality and integrity risks.

Generated by OpenCVE AI on August 12, 2026 at 19:38 UTC.

Remediation

Vendor Solution

Users should update the Mira app to the latest version iOS v3.5.18 / Android v4.5.18. Firmware v01.07.01.53 is updated via the app when the device is connected. No additional action is required.


OpenCVE Recommended Actions

  • Update the Mira Android application to version 4.5.18 to remove the hard‑coded credentials.
  • Apply the firmware update to v01.07.01.53 via the app to secure the device.
  • If a software update cannot be applied immediately, restrict the device’s network access so that its health profiles cannot be read or modified by remote actors.

Generated by OpenCVE AI on August 12, 2026 at 19:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Quanovate Tech
Quanovate Tech mira Android App
Quanovate Tech mira Firmware
Vendors & Products Quanovate Tech
Quanovate Tech mira Android App
Quanovate Tech mira Firmware

Wed, 12 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 11 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
Description The distributed Mira Android APK v4.5.15.4 allows an attacker read/write access to reproductive health profiles from internet connected hosts, which could result in forgery, deletion, or destruction of health information.
Title Mira Hormone Monitor, Mira Android App Use of Hard-coded Credentials
Weaknesses CWE-798
References
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Quanovate Tech Mira Android App Mira Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2026-08-12T12:52:01.874Z

Reserved: 2026-08-03T16:54:56.478Z

Link: CVE-2026-67568

cve-icon Vulnrichment

Updated: 2026-08-12T12:51:30.360Z

cve-icon NVD

Status : Received

Published: 2026-08-11T22:18:54.877

Modified: 2026-08-12T14:18:33.557

Link: CVE-2026-67568

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T09:49:02Z

Weaknesses
  • CWE-798

    Use of Hard-coded Credentials