CVE-2026-66832: Mira Hormone Monitor, Mira Android App Use of GET request method with sensitive query strings

Published Aug 11, 2026
·
Updated

When the Mira Android app opens in-app WebView content (e.g., shop redirect flows), the user's live session token is appended to the URL as a query string parameter, and a persistent user identifier is included in the WebView's User-Agent header. Both are then transmitted to third-party web properties, referrer logs, and any JavaScript running in the WebView context.

Affected Software

1 affected component
Mira Android App

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in v4.5.18
  2. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in v3.5.18

Event History

Aug 11, 2026
CVE Published
via MITRE·08:49 PM
Data Sourced
via MITRE·08:49 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·09:17 PM
DescriptionSeverityWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-66832?

CVE-2026-66832 has a medium severity rating of 6.5.

2

How can I mitigate CVE-2026-66832 in the Mira Android app?

Mitigation for CVE-2026-66832 involves avoiding the use of GET requests for sensitive information and ensuring secure transmission methods.

3

What are the risks associated with CVE-2026-66832?

The risks of CVE-2026-66832 include exposure of sensitive user session tokens and persistent identifiers to third-party web properties.

4

When was CVE-2026-66832 published?

CVE-2026-66832 was published on August 11, 2026.

5

Which software is affected by CVE-2026-66832?

CVE-2026-66832 affects the Mira Android App.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203