CVE-2026-66340: Mira Hormone Monitor, Mira Android App Improper restriction of excessive authentication attempts
The Mira cloud authentication endpoints do not enforce per-account rate limiting, per-IP throttling, or account lockout after repeated failed login attempts. An attacker can use brute-force methods to obtain gain access to user accounts.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 4.5.18 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 3.5.18
Event History
Frequently Asked Questions
What is the severity of CVE-2026-66340?
CVE-2026-66340 has a medium severity score of 5.3.
What is the risk associated with CVE-2026-66340?
The risk associated with CVE-2026-66340 is rated at 27.
How does CVE-2026-66340 affect the Mira Android App?
CVE-2026-66340 affects the Mira Android App by allowing brute-force attacks due to improper restriction of excessive authentication attempts.
What types of account protection mechanisms are missing in CVE-2026-66340?
CVE-2026-66340 lacks per-account rate limiting, per-IP throttling, and account lockout after repeated failed login attempts.
How can I mitigate the vulnerability identified in CVE-2026-66340?
Mitigation for CVE-2026-66340 involves implementing proper rate limiting and account lockout mechanisms on Mira cloud authentication endpoints.