Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.3

CVE-2026-68067: Mira Android App Passwords Not Verified Correctly

CVE-2026-68067 · published 23 days ago
Summary

The Mira Android app has a weak password verification system. This means an attacker could use an email address to access hormone records and account settings. To stay secure, update the app to the latest version, and use strong, unique passwords for all accounts.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
quanovate tech inc. (operating as mira / mira care) mira firmware 1.7.1.47
quanovate tech inc. (operating as mira / mira care) mira android app 4.5.15.4
Original advisory text
Mira Hormone Monitor, Mira Android App Weak Authentication
The login endpoint on the Mira cloud API accepts any format-valid string in the password field and returns a live active session token for the account matching the supplied email address. An attacker could use an email address to control cloud accounts and access hormone record information and account settings.
Severity
9.3 Critical
CVSS 3.1: 9.8 (NVD)
CVSS 4.0: 9.3 (NVD)
Exploitation
EPSS <1%
Type
CWE-1390Weak Authentication
Timeline
Published11 Aug 2026
Updated30 Aug 2026
First seen11 Aug 2026
Sources
CVE-2026-68067 · MITRE
Monitor software like this
Free during beta