CVE-2026-66832: Mira Hormone Monitor, Mira Android App Use of GET request method with sensitive query strings
When the Mira Android app opens in-app WebView content (e.g., shop redirect flows), the user's live session token is appended to the URL as a query string parameter, and a persistent user identifier is included in the WebView's User-Agent header. Both are then transmitted to third-party web properties, referrer logs, and any JavaScript running in the WebView context.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in v4.5.18 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in v3.5.18
Event History
Frequently Asked Questions
What is the severity of CVE-2026-66832?
CVE-2026-66832 has a medium severity rating of 6.5.
How can I mitigate CVE-2026-66832 in the Mira Android app?
Mitigation for CVE-2026-66832 involves avoiding the use of GET requests for sensitive information and ensuring secure transmission methods.
What are the risks associated with CVE-2026-66832?
The risks of CVE-2026-66832 include exposure of sensitive user session tokens and persistent identifiers to third-party web properties.
When was CVE-2026-66832 published?
CVE-2026-66832 was published on August 11, 2026.
Which software is affected by CVE-2026-66832?
CVE-2026-66832 affects the Mira Android App.