View CSAF

Summary

Successful exploitation of these vulnerabilities could allow an attacker to access unauthorized health profile information, make changes to health information, cause a denial-of-service condition, disclose session token information, and obtain control of user accounts.

The following versions of Mira Hormone Monitor, Mira Android App are affected:

  • Mira Monitor Firmware 1.7.1.47 (CVE-2026-66875, CVE-2026-66098, CVE-2026-67558, CVE-2026-67568, CVE-2026-68067, CVE-2026-66340, CVE-2026-64934, CVE-2026-66832)
  • Mira Android App 4.5.15.4 (CVE-2026-66875, CVE-2026-66098, CVE-2026-67558, CVE-2026-67568, CVE-2026-68067, CVE-2026-66340, CVE-2026-64934, CVE-2026-66832)

CVSS

Vendor

Equipment

Vulnerabilities

v3 9.8

Quanovate Tech Inc. (operating as Mira / Mira Care)

Mira Hormone Monitor, Mira Android App

Missing Authentication for Critical Function, Authentication Bypass by Spoofing, Use of Hard-coded Credentials, Weak Authentication, Improper Restriction of Excessive Authentication Attempts, Reliance on Untrusted Inputs in a Security Decision, Use of GET Request Method With Sensitive Query Strings

Background

  • Critical Infrastructure Sectors: Healthcare and Public Health
  • Countries/Areas Deployed: Worldwide
  • Company Headquarters Location: United States

Vulnerabilities

Expand All +

CVE-2026-66875

In the Mira hormone monitor device firmware v1.7.1.47 build 01070147, a remote unauthenticated attacker within BLE range (approximately 10–30 meters) can silently rebind the device to an attacker-controlled account, extract stored hormone measurements in cleartext, cause a denial-of-service via malformed or undocumented command opcodes, and passively track the user via a static random BLE address that never rotates.

View CVE Details

Affected Products

Mira Hormone Monitor, Mira Android App

Vendor:

Quanovate Tech Inc. (operating as Mira / Mira Care)

Product Version:

Quanovate Tech Inc. (operating as Mira / Mira Care) Mira Monitor Firmware: 1.7.1.47, Quanovate Tech Inc. (operating as Mira / Mira Care) Mira Android App: 4.5.15.4

Product Status:

known_affected

Remediations

Mitigation

Users should update the Mira app to the latest version iOS v3.5.18 / Android v4.5.18. Firmware v01.07.01.53 is updated via the app when the device is connected. No additional action is required.

Relevant CWE: CWE-306 Missing Authentication for Critical Function

Metrics

CVSS Version

Base Score

Base Severity

Vector String

3.1

8.8

HIGH

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

4.0

8.7

HIGH

CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

CVE-2026-66098

The Mira hormone monitor device firmware accepts a 0x01 write from any BLE central without authentication, causing the device to reboot into bootloader mode. An attacker could cause a denial-of-service condition or disrupt ovulation tracking and fertility monitoring workflow.

View CVE Details

Affected Products

Mira Hormone Monitor, Mira Android App

Vendor:

Quanovate Tech Inc. (operating as Mira / Mira Care)

Product Version:

Quanovate Tech Inc. (operating as Mira / Mira Care) Mira Monitor Firmware: 1.7.1.47, Quanovate Tech Inc. (operating as Mira / Mira Care) Mira Android App: 4.5.15.4

Product Status:

known_affected

Remediations

Mitigation

Users should update the Mira app to the latest version iOS v3.5.18 / Android v4.5.18. Firmware v01.07.01.53 is updated via the app when the device is connected. No additional action is required.

Relevant CWE: CWE-306 Missing Authentication for Critical Function

Metrics

CVSS Version

Base Score

Base Severity

Vector String

3.1

6.5

MEDIUM

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

4.0

7.1

HIGH

CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

CVE-2026-67558

The Mira Android companion app v4.5.15.4 identifies the paired Mira hormone analyzer by performing a substring match against the BLE advertisement name only, with no cryptographic peripheral authentication, MAC allowlist, or bonded-identity check. An attacker could capture live session token information and inject forged hormone measurements into the victim's cloud record and clinical trend view.

View CVE Details

Affected Products

Mira Hormone Monitor, Mira Android App

Vendor:

Quanovate Tech Inc. (operating as Mira / Mira Care)

Product Version:

Quanovate Tech Inc. (operating as Mira / Mira Care) Mira Monitor Firmware: 1.7.1.47, Quanovate Tech Inc. (operating as Mira / Mira Care) Mira Android App: 4.5.15.4

Product Status:

known_affected

Remediations

Mitigation

Users should update the Mira app to the latest version iOS v3.5.18 / Android v4.5.18. Firmware v01.07.01.53 is updated via the app when the device is connected. No additional action is required.

Relevant CWE: CWE-290 Authentication Bypass by Spoofing

Metrics

CVSS Version

Base Score

Base Severity

Vector String

3.1

7.4

HIGH

CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N

4.0

8.2

HIGH

CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:A/VC:H/VI:L/VA:N/SC:H/SI:L/SA:N

CVE-2026-67568

The distributed Mira Android APK v4.5.15.4 allows an attacker read/write access to reproductive health profiles from internet connected hosts, which could result in forgery, deletion, or destruction of health information.

View CVE Details

Affected Products

Mira Hormone Monitor, Mira Android App

Vendor:

Quanovate Tech Inc. (operating as Mira / Mira Care)

Product Version:

Quanovate Tech Inc. (operating as Mira / Mira Care) Mira Monitor Firmware: 1.7.1.47, Quanovate Tech Inc. (operating as Mira / Mira Care) Mira Android App: 4.5.15.4

Product Status:

known_affected

Remediations

Mitigation

Users should update the Mira app to the latest version iOS v3.5.18 / Android v4.5.18. Firmware v01.07.01.53 is updated via the app when the device is connected. No additional action is required.

Relevant CWE: CWE-798 Use of Hard-coded Credentials

Metrics

CVSS Version

Base Score

Base Severity

Vector String

3.1

9.1

CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

4.0

9.3

CRITICAL

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N

CVE-2026-68067

The login endpoint on the Mira cloud API accepts any format-valid string in the password field and returns a live active session token for the account matching the supplied email address. An attacker could use an email address to control cloud accounts and access hormone record information and account settings.

View CVE Details

Affected Products

Mira Hormone Monitor, Mira Android App

Vendor:

Quanovate Tech Inc. (operating as Mira / Mira Care)

Product Version:

Quanovate Tech Inc. (operating as Mira / Mira Care) Mira Monitor Firmware: 1.7.1.47, Quanovate Tech Inc. (operating as Mira / Mira Care) Mira Android App: 4.5.15.4

Product Status:

known_affected

Remediations

Mitigation

Users should update the Mira app to the latest version iOS v3.5.18 / Android v4.5.18. Firmware v01.07.01.53 is updated via the app when the device is connected. No additional action is required.

Relevant CWE: CWE-1390 Weak Authentication

Metrics

CVSS Version

Base Score

Base Severity

Vector String

3.1

9.8

CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

4.0

9.3

CRITICAL

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

CVE-2026-66340

The Mira cloud authentication endpoints do not enforce per-account rate limiting, per-IP throttling, or account lockout after repeated failed login attempts. An attacker can use brute-force methods to obtain gain access to user accounts.

View CVE Details

Affected Products

Mira Hormone Monitor, Mira Android App

Vendor:

Quanovate Tech Inc. (operating as Mira / Mira Care)

Product Version:

Quanovate Tech Inc. (operating as Mira / Mira Care) Mira Monitor Firmware: 1.7.1.47, Quanovate Tech Inc. (operating as Mira / Mira Care) Mira Android App: 4.5.15.4

Product Status:

known_affected

Remediations

Mitigation

Users should update the Mira app to the latest version iOS v3.5.18 / Android v4.5.18. Firmware v01.07.01.53 is updated via the app when the device is connected. No additional action is required.

Relevant CWE: CWE-307 Improper Restriction of Excessive Authentication Attempts

Metrics

CVSS Version

Base Score

Base Severity

Vector String

3.1

5.3

MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

4.0

6.9

MEDIUM

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N

CVE-2026-64934

The Mira cloud API accepts the firmware version reported by the companion app as authoritative for a given device, without independently attesting the version from the device itself. An authenticated attacker could submit arbitrary firmware version strings for their own device, allowing them to evade vendor-side vulnerable-fleet analytics, suppress security update prompts to the user, and misrepresent patch-adoption metrics.

View CVE Details

Affected Products

Mira Hormone Monitor, Mira Android App

Vendor:

Quanovate Tech Inc. (operating as Mira / Mira Care)

Product Version:

Quanovate Tech Inc. (operating as Mira / Mira Care) Mira Monitor Firmware: 1.7.1.47, Quanovate Tech Inc. (operating as Mira / Mira Care) Mira Android App: 4.5.15.4

Product Status:

known_affected

Remediations

Mitigation

Users should update the Mira app to the latest version iOS v3.5.18 / Android v4.5.18. Firmware v01.07.01.53 is updated via the app when the device is connected. No additional action is required.

Relevant CWE: CWE-807 Reliance on Untrusted Inputs in a Security Decision

Metrics

CVSS Version

Base Score

Base Severity

Vector String

3.1

4.3

MEDIUM

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

4.0

5.3

MEDIUM

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N

CVE-2026-66832

When the Mira Android app opens in-app WebView content (e.g., shop redirect flows), the user's live session token is appended to the URL as a query string parameter, and a persistent user identifier is included in the WebView's User-Agent header. Both are then transmitted to third-party web properties, referrer logs, and any JavaScript running in the WebView context.

View CVE Details

Affected Products

Mira Hormone Monitor, Mira Android App

Vendor:

Quanovate Tech Inc. (operating as Mira / Mira Care)

Product Version:

Quanovate Tech Inc. (operating as Mira / Mira Care) Mira Monitor Firmware: 1.7.1.47, Quanovate Tech Inc. (operating as Mira / Mira Care) Mira Android App: 4.5.15.4

Product Status:

known_affected

Remediations

Mitigation

Users should update the Mira app to the latest version iOS v3.5.18 / Android v4.5.18. Firmware v01.07.01.53 is updated via the app when the device is connected. No additional action is required.

Relevant CWE: CWE-598 Use of GET Request Method With Sensitive Query Strings

Metrics

CVSS Version

Base Score

Base Severity

Vector String

3.1

6.5

MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

4.0

6.9

MEDIUM

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

Acknowledgments

  • Gigi Xiaoqing Liu, Muzzammil Mohammed, Narmina Karimova, and En Mong of Northeastern University SPQR Lab reported these vulnerabilities to Quanovate Tech

Legal Notice and Terms of Use

This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy).

Recommended Practices

CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities.

Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.

Locate control system networks and remote devices behind firewalls and isolating them from business networks.

When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.

CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.

CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.

CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.

Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.

Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.

CISA also recommends users take the following measures to protect themselves from social engineering attacks:

Do not click web links or open attachments in unsolicited email messages.

Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams.

Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks.

No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time.

Revision History

  • Initial Release Date: 2026-08-11

Date

Revision

Summary

2026-08-11

1

Initial Publication

Legal Notice and Terms of Use