CVE-2026-68067
Mira Hormone Monitor, Mira Android App Weak Authentication
The login endpoint on the Mira cloud API accepts any format-valid string in the password field and returns a live active session token for the account matching the supplied email address. An attacker could use an email address to control cloud accounts and access hormone record information and account settings.
Coverage 1 source
-
2026-08-11
CISA Cybersecurity Advisories
high
Mira Hormone Monitor, Mira Android App
Multiple vulnerabilities in Mira Hormone Monitor and Mira Android App could allow unauthorized access and control.
Mentioned with
CVE-2026-66098 CVE-2026-66340 CVE-2026-66875 CVE-2026-67558 CVE-2026-67568
Also covered
- CVE-2026-86950 Apple iOS and iPadOS
- CVE-2023-6548 Cloud Software Group NetScaler ADC
- CVE-2023-25608 Fortinet FortiAP-W2
- CVE-2026-88772 Memory overflow vulnerability leading to Remote Code Execution or Denial of Service
- CVE-2026-88771 A remote code execution vulnerability exists due to improper input validation, which can allow an unauthenticated attacker to execute arbitrary commands