CVE-2026-66098: Mira Hormone Monitor, Mira Android App Missing authentication for critical function
The Mira hormone monitor device firmware accepts a 0x01 write from any BLE central without authentication, causing the device to reboot into bootloader mode. An attacker could cause a denial-of-service condition or disrupt ovulation tracking and fertility monitoring workflow.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Mira Android Appto a version that resolves this vulnerability.Fixed in 4.5.18 - Upgrade
Upgrade
Mira iOS Appto a version that resolves this vulnerability.Fixed in 3.5.18
Event History
Frequently Asked Questions
What is the severity of CVE-2026-66098?
CVE-2026-66098 has a medium severity score of 6.5.
What is CVE-2026-66098 about?
CVE-2026-66098 involves the Mira hormone monitor device firmware lacking authentication for critical BLE functions, allowing unauthorized access.
What impact can CVE-2026-66098 have on users?
CVE-2026-66098 can lead to denial-of-service, disrupting ovulation tracking and fertility monitoring.
How can I mitigate CVE-2026-66098?
To mitigate CVE-2026-66098, ensure that any updates from the manufacturer include a firmware patch that addresses the authentication issue.
Who is affected by CVE-2026-66098?
Users of the Mira hormone monitor device and app are affected by CVE-2026-66098 due to the lack of authentication.