Mira Hormone Monitor, Mira Android App
Mira Hormone Monitor and Android App have multiple critical vulnerabilities.
Summary
Multiple critical vulnerabilities have been discovered in the Mira Hormone Monitor firmware (v1.7.1.47) and the Mira Android App (v4.5.15.4). These flaws could allow attackers to access, modify, or delete health data, steal session tokens, and gain control of user accounts. The vulnerabilities stem from issues like missing authentication, authentication bypass, hard-coded credentials, and weak authentication mechanisms.
Full text
ICS Medical Advisory Mira Hormone Monitor, Mira Android App Release DateAugust 11, 2026 Alert CodeICSMA-26-223-01 Related topics: Industrial Control System Vulnerabilities , Industrial Control Systems View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to access unauthorized health profile information, make changes to health information, cause a denial-of-service condition, disclose session token information, and obtain control of user accounts. The following versions of Mira Hormone Monitor, Mira Android App are affected: Mira Monitor Firmware 1.7.1.47 (CVE-2026-66875, CVE-2026-66098, CVE-2026-67558, CVE-2026-67568, CVE-2026-68067, CVE-2026-66340, CVE-2026-64934, CVE-2026-66832) Mira Android App 4.5.15.4 (CVE-2026-66875, CVE-2026-66098, CVE-2026-67558, CVE-2026-67568, CVE-2026-68067, CVE-2026-66340, CVE-2026-64934, CVE-2026-66832) CVSS Vendor Equipment Vulnerabilities v3 9.8 Quanovate Tech Inc. (operating as Mira / Mira Care) Mira Hormone Monitor, Mira Android App Missing Authentication for Critical Function, Authentication Bypass by Spoofing, Use of Hard-coded Credentials, Weak Authentication, Improper Restriction of Excessive Authentication Attempts, Reliance on Untrusted Inputs in a Security Decision, Use of GET Request Method With Sensitive Query Strings Background Critical Infrastructure Sectors: Healthcare and Public Health Countries/Areas Deployed: Worldwide Company Headquarters Location: United States Vulnerabilities Expand All + CVE-2026-66875 In the Mira hormone monitor device firmware v1.7.1.47 build 01070147, a remote unauthenticated attacker within BLE range (approximately 10–30 meters) can silently rebind the device to an attacker-controlled account, extract stored hormone measurements in cleartext, cause a denial-of-service via malformed or undocumented command opcodes, and passively track the user via a static random BLE address that never rotates. View CVE Details Affected Products Mira Hormone Monitor, Mira Android App Vendor:Quanovate Tech Inc. (operating as Mira / Mira Care) Product Version:Quanovate Tech Inc. (operating as Mira / Mira Care) Mira Monitor Firmware: 1.7.1.47, Quanovate Tech Inc. (operating as Mira / Mira Care) Mira Android App: 4.5.15.4 Product Status:known_affected Remediations MitigationUsers should update the Mira app to the latest version iOS v3.5.18 / Android v4.5.18. Firmware v01.07.01.53 is updated via the app when the device is connected. No additional action is required. Relevant CWE: CWE-306 Missing Authentication for Critical Function Metrics CVSS Version Base Score Base Severity Vector String 3.1 8.8 HIGH CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H 4.0 8.7 HIGH CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N CVE-2026-66098 The Mira hormone monitor device firmware accepts a 0x01 write from any BLE central without authentication, causing the device to reboot into bootloader mode. An attacker could cause a denial-of-service condition or disrupt ovulation tracking and fertility monitoring workflow. View CVE Details Affected Products Mira Hormone Monitor, Mira Android App Vendor:Quanovate Tech Inc. (operating as Mira / Mira Care) Product Version:Quanovate Tech Inc. (operating as Mira / Mira Care) Mira Monitor Firmware: 1.7.1.47, Quanovate Tech Inc. (operating as Mira / Mira Care) Mira Android App: 4.5.15.4 Product Status:known_affected Remediations MitigationUsers should update the Mira app to the latest version iOS v3.5.18 / Android v4.5.18. Firmware v01.07.01.53 is updated via the app when the device is connected. No additional action is required. Relevant CWE: CWE-306 Missing Authentication for Critical Function Metrics CVSS Version Base Score Base Severity Vector String 3.1 6.5 MEDIUM CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H 4.0 7.1 HIGH CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N CVE-2026-67558 The Mira Android companion app v4.5.15.4 identifies the paired Mira hormone analyzer by performing a substring match against the BLE advertisement name only, with no cryptographic peripheral authentication, MAC allowlist, or bonded-identity check. An attacker could capture live session token information and inject forged hormone measurements into the victim's cloud record and clinical trend view. View CVE Details Affected Products Mira Hormone Monitor, Mira Android App Vendor:Quanovate Tech Inc. (operating as Mira / Mira Care) Product Version:Quanovate Tech Inc. (operating as Mira / Mira Care) Mira Monitor Firmware: 1.7.1.47, Quanovate Tech Inc. (operating as Mira / Mira Care) Mira Android App: 4.5.15.4 Product Status:known_affected Remediations MitigationUsers should update the Mira app to the latest version iOS v3.5.18 / Android v4.5.18. Firmware v01.07.01.53 is updated via the app when the device is connected. No additional action is required. Relevant CWE: CWE-290 Authentication Bypass by Spoofing Metrics CVSS Version Base Score Base Severity Vector String 3.1 7.4 HIGH CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N 4.0 8.2 HIGH CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:A/VC:H/VI:L/VA:N/SC:H/SI:L/SA:N CVE-2026-67568 The distributed Mira Android APK v4.5.15.4 allows an attacker read/write access to reproductive health profiles from internet connected hosts, which could result in forgery, deletion, or destruction of health information. View CVE Details Affected Products Mira Hormone Monitor, Mira Android App Vendor:Quanovate Tech Inc. (operating as Mira / Mira Care) Product Version:Quanovate Tech Inc. (operating as Mira / Mira Care) Mira Monitor Firmware: 1.7.1.47, Quanovate Tech Inc. (operating as Mira / Mira Care) Mira Android App: 4.5.15.4 Product Status:known_affected Remediations MitigationUsers should update the Mira app to the latest version iOS v3.5.18 / Android v4.5.18. Firmware v01.07.01.53 is updated via the app when the device is connected. No additional action is required. Relevant CWE: CWE-798 Use of Hard-coded Credentials Metrics CVSS Version Base Score Base Severity Vector String 3.1 9.1 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N 4.0 9.3 CRITICAL CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N CVE-2026-68067 The login endpoint on the Mira cloud API accepts any format-valid string in the password field and returns a live active session token for the account matching the supplied email address. An attacker could use an email address to control cloud accounts and access hormone record information and account settings. View CVE Details Affected Products Mira Hormone Monitor, Mira Android App Vendor:Quanovate Tech Inc. (operating as Mira / Mira Care) Product Version:Quanovate Tech Inc. (operating as Mira / Mira Care) Mira Monitor Firmware: 1.7.1.47, Quanovate Tech Inc. (operating as Mira / Mira Care) Mira Android App: 4.5.15.4 Product Status:known_affected Remediations MitigationUsers should update the Mira app to the latest version iOS v3.5.18 / Android v4.5.18. Firmware v01.07.01.53 is updated via the app when the device is connected. No additional action is required. Relevant CWE: CWE-1390 Weak Authentication Metrics CVSS Version Base Score Base Severity Vector String 3.1 9.8 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H 4.0 9.3 CRITICAL CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N CVE-2026-66340 The Mira cloud authentication endpoints do not enforce per-account rate limiting, per-IP throttling, or account lockout after repeated failed login attempts. An attacker can use brute-force methods to obtain gain access to user accounts. View CVE Details Affected Products Mira Hormone Monitor, Mira Android App Vendor:Quanovate Tech Inc. (operating as Mira / Mira Care) Product Version:Quanovate Tech Inc. (operating as Mira / Mira Care) Mira Monitor Firmware: 1.7.1.47, Quanovate Tech Inc. (operating as Mira / Mira Care) Mira Android App: 4.5.15.4 Product Status:known_affected Remediations MitigationUsers should update the Mira app to the latest version iOS v3.5.18 / Android v4.5.18. Fir
Indicators of Compromise
- cve — CVE-2026-66875
- cve — CVE-2026-66098
- cve — CVE-2026-67558
- cve — CVE-2026-67568
- cve — CVE-2026-68067
- cve — CVE-2026-66340
- cve — CVE-2026-64934
- cve — CVE-2026-66832