CVE-2026-64934: Mira Hormone Monitor, Mira Android App Reliance on untrusted inputs in a security decision
The Mira cloud API accepts the firmware version reported by the companion app as authoritative for a given device, without independently attesting the version from the device itself. An authenticated attacker could submit arbitrary firmware version strings for their own device, allowing them to evade vendor-side vulnerable-fleet analytics, suppress security update prompts to the user, and misrepresent patch-adoption metrics.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 4.5.18 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 3.5.18
Event History
Frequently Asked Questions
What is the severity of CVE-2026-64934?
The severity of CVE-2026-64934 is medium with a score of 4.3.
How do I fix CVE-2026-64934?
To mitigate CVE-2026-64934, ensure that the Mira cloud API independently validates the firmware version instead of solely relying on the version reported by the Android app.
What impact does CVE-2026-64934 have on my device?
CVE-2026-64934 allows an authenticated attacker to submit arbitrary firmware version strings, potentially leading to security evasion.
Which software is affected by CVE-2026-64934?
CVE-2026-64934 affects the Mira cloud API and the Mira Android app.
Is CVE-2026-64934 related to untrusted inputs?
Yes, CVE-2026-64934 involves the reliance on untrusted inputs in a security decision made by the Mira cloud API.