Mira vulnerabilities
6 CVEs tracked
Mira (hormone monitor and companion app) appears in ctiaze reporting with severe vulnerabilities spanning both device (BLE) and cloud API layers. The main theme is a systemic lack of proper authentication and authorization: a critical authentication bypass in the cloud API (CVE-2026-68067) and silent device rebinding over BLE (CVE-2026-66875) are top concerns. This is compounded by weak BLE device identification in the Android app (CVE-2026-67558), a BLE-triggered DoS (CVE-2026-66098), and live session token leakage via WebView (CVE-2026-66832). Defenders must urgently mitigate risks of unrestricted account takeover, theft of sensitive reproductive health data, and disruption of cycle tracking.
Azərbaycanca: Mira (hormon analizatoru və müşayiət tətbiqi) ctiaze hesabatlarımızda həm cihaz (BLE), həm də bulud API səviyyəsində ciddi zəifliklərlə qeyd olunur. Əsas mövzu autentifikasiya və icazə mexanizmlərinin çatışmazlığıdır: bulud API-də kritik autentifikasiya bypass (CVE-2026-68067) və BLE üzərindən cihazın səssizcə ələ keçirilməsi (CVE-2026-66875) xüsusi diqqət tələb edir. Buna əlavə olaraq, Android tətbiqində BLE vasitəsilə cihazın zəif identifikasiyası (CVE-2026-67558) və DoS hücumu (CVE-2026-66098), həmçinin WebView vasitəsilə sessiya tokenlərinin sızması (CVE-2026-66832) mövcuddur. Müdafiəçilər istifadəçi hesablarının qeyri-məhdud ələ keçirilməsi, reproduktiv sağlamlıq məlumatlarının oğurlanması və həyat dövrünün izlənməsinin pozulması risklərinə qarşı təcili tədbirlər görməlidir.
This vendor's CVEs6
This hub is built from skopnix's own reporting on Mira: the overview is AI-written from that coverage and every CVE links to its grounded explainer. KEV status comes from CISA's Known Exploited Vulnerabilities catalog and EPSS from FIRST — vendor, version and score details are never invented.