CVE-2026-67568: Mira Hormone Monitor, Mira Android App Use of Hard-coded Credentials
The distributed Mira Android APK v4.5.15.4 allows an attacker read/write access to reproductive health profiles from internet connected hosts, which could result in forgery, deletion, or destruction of health information.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Mira iOS Appto a version that resolves this vulnerability.Fixed in 3.5.18
Event History
Frequently Asked Questions
What is the severity of CVE-2026-67568?
The severity of CVE-2026-67568 is rated as critical with a score of 9.1.
How do I fix CVE-2026-67568?
To fix CVE-2026-67568, update the Mira Android App to the latest version that no longer uses hard-coded credentials.
What systems are affected by CVE-2026-67568?
CVE-2026-67568 affects the Mira Android App, specifically version 4.5.15.4 and earlier.
What are the risks associated with CVE-2026-67568?
The risks associated with CVE-2026-67568 include unauthorized access to reproductive health profiles, leading to potential forgery and destruction of health information.
Is user interaction required to exploit CVE-2026-67568?
No, user interaction is not required to exploit CVE-2026-67568, as it allows remote access without user involvement.