CVE-2026-68067: Mira Hormone Monitor, Mira Android App Weak Authentication
The login endpoint on the Mira cloud API accepts any format-valid string in the password field and returns a live active session token for the account matching the supplied email address. An attacker could use an email address to control cloud accounts and access hormone record information and account settings.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in v4.5.18 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in v3.5.18
Event History
Frequently Asked Questions
What is the severity of CVE-2026-68067?
The severity of CVE-2026-68067 is critical with a score of 9.8.
How do I fix CVE-2026-68067?
To fix CVE-2026-68067, implement proper authentication mechanisms to validate passwords before issuing session tokens.
What systems are affected by CVE-2026-68067?
CVE-2026-68067 affects the Mira Hormone Monitor and the Mira Android App.
What type of vulnerability is CVE-2026-68067?
CVE-2026-68067 is classified as a weak authentication vulnerability.
What could an attacker do with CVE-2026-68067?
An attacker could exploit CVE-2026-68067 to gain unauthorized access to user accounts and sensitive hormone record information.