Description
The login endpoint on the Mira cloud API accepts any format-valid string in the password field and returns a live active session token for the account matching the supplied email address. An attacker could use an email address to control cloud accounts and access hormone record information and account settings.
Published: 2026-08-11
Score: 9.3 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw resides in the Mira cloud API login; any properly formed string is accepted as a password, and the endpoint returns an active session token for the account corresponding to the supplied email. This weak authentication mechanism allows an attacker to obtain legitimate session credentials for any user simply by guessing or selecting an email address. The consequence is unauthorized access to sensitive hormone records and account settings, a serious breach of confidentiality. The weakness is classified as CWE-1390, reflecting improper handling of input validation for authentication.

Affected Systems

The vulnerability affects the Mira Android App and associated Mira Firmware delivered by Quanovate Tech Inc. Users running older versions of the Android app before v4.5.18 (and corresponding iOS app before v3.5.18) are impacted. Earlier firmware builds prior to v01.07.01.53 also inherit the issue, as they are updated through the app when the device is connected. Updating to the latest app or firmware releases resolves the problem.

Risk and Exploitability

The CVSS score of 9.3 denotes critical impact, while the EPSS score of less than 1% indicates a low but non‑zero likelihood of exploitation at this time. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires only remote access to the exposed API endpoint; no local privileges or physical access are needed. An attacker can remotely craft a password payload, submit it alongside any target email, and immediately receive a valid session token, enabling full access to the victim's hormone data and settings.

Generated by OpenCVE AI on August 12, 2026 at 19:23 UTC.

Remediation

Vendor Solution

Users should update the Mira app to the latest version iOS v3.5.18 / Android v4.5.18. Firmware v01.07.01.53 is updated via the app when the device is connected. No additional action is required.


OpenCVE Recommended Actions

  • Apply the latest Android app update (v4.5.18) or iOS app update (v3.5.18) from Quanovate; firmware versions prior to v01.07.01.53 should be upgraded via the app when the device connects.
  • Ensure that future app and firmware releases enforce strong password validation and consider implementing account lockout or rate limiting on the login endpoint.
  • If a timely update is not possible, temporarily disable the cloud API or restrict access to authenticated users only until the fix is applied.

Generated by OpenCVE AI on August 12, 2026 at 19:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Quanovate Tech
Quanovate Tech mira Android App
Quanovate Tech mira Firmware
Vendors & Products Quanovate Tech
Quanovate Tech mira Android App
Quanovate Tech mira Firmware

Wed, 12 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 11 Aug 2026 21:30:00 +0000

Type Values Removed Values Added
Description The login endpoint on the Mira cloud API accepts any format-valid string in the password field and returns a live active session token for the account matching the supplied email address. An attacker could use an email address to control cloud accounts and access hormone record information and account settings.
Title Mira Hormone Monitor, Mira Android App Weak Authentication
Weaknesses CWE-1390
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Quanovate Tech Mira Android App Mira Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2026-08-12T12:53:26.573Z

Reserved: 2026-08-03T16:54:56.485Z

Link: CVE-2026-68067

cve-icon Vulnrichment

Updated: 2026-08-12T12:53:22.707Z

cve-icon NVD

Status : Received

Published: 2026-08-11T22:18:55.017

Modified: 2026-08-12T14:18:33.687

Link: CVE-2026-68067

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T09:49:03Z

Weaknesses