CVE-2026-67558: Mira Hormone Monitor, Mira Android App Authentication bypass by spoofing
The Mira Android companion app v4.5.15.4 identifies the paired Mira hormone analyzer by performing a substring match against the BLE advertisement name only, with no cryptographic peripheral authentication, MAC allowlist, or bonded-identity check. An attacker could capture live session token information and inject forged hormone measurements into the victim's cloud record and clinical trend view.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Mira Android Appto a version that resolves this vulnerability.Fixed in v4.5.18 - Upgrade
Upgrade
Mira iOS Appto a version that resolves this vulnerability.Fixed in v3.5.18
Event History
Frequently Asked Questions
What is the severity of CVE-2026-67558?
CVE-2026-67558 has a severity rating of high with a score of 7.4.
How can I fix CVE-2026-67558?
To mitigate CVE-2026-67558, ensure that the Mira Android app is updated to the latest version with enhanced authentication features.
What type of attack does CVE-2026-67558 facilitate?
CVE-2026-67558 allows for an authentication bypass through spoofing of the Mira hormone analyzer.
Is user interaction required to exploit CVE-2026-67558?
Exploitation of CVE-2026-67558 does require user interaction to initiate the spoofing.
What impact does CVE-2026-67558 have on data confidentiality?
CVE-2026-67558 can lead to complete disclosure of sensitive session token information, affecting data confidentiality.