AllCyberNews

CVE-2026-66340

Mira Hormone Monitor, Mira Android App Improper restriction of excessive authentication attempts

CVSS 6.9 medium · Quanovate Tech Inc. (operating as Mira / Mira Care) Mira Firmware · published 2026-08-11

The Mira cloud authentication endpoints do not enforce per-account rate limiting, per-IP throttling, or account lockout after repeated failed login attempts. An attacker can use brute-force methods to obtain gain access to user accounts.

Coverage 1 source

  1. 2026-08-11 CISA Cybersecurity Advisories high Mira Hormone Monitor, Mira Android App

    Multiple vulnerabilities in Mira Hormone Monitor and Mira Android App could allow unauthorized access and control.

Mentioned with

CVE-2026-66098 CVE-2026-66875 CVE-2026-67558 CVE-2026-67568 CVE-2026-68067

Also covered