criticalOther

Mira Hormone Monitor and Mira Android App Multiple Vulnerabilities

First seen Aug 12, 2026 · Updated Aug 12, 2026 · CVSS 9.8

medical-deviceIoTBLEauthentication-bypasshard-coded-credentialssession-hijackinghealthcareICS-medical-advisoryprivacy

CISA disclosed eight vulnerabilities in the Mira Hormone Monitor firmware and companion Mira Android App, including missing BLE authentication, hard-coded credentials, and a broken login endpoint that returns valid session tokens for any password. Successful exploitation could allow attackers to hijack user accounts, exfiltrate or forge sensitive reproductive health data, track users physically via BLE, and cause denial-of-service on the device.

Technical Analysis

The most severe issues include CVE-2026-68067 (CVSS 9.8), where the Mira cloud login endpoint accepts any format-valid password and returns an active session token for the matching email, enabling trivial account takeover, and CVE-2026-67568 (CVSS 9.1), involving hard-coded credentials (CWE-798) allowing read/write access to reproductive health profiles from the internet. CVE-2026-66875 (CVSS 8.8) exposes the BLE firmware to unauthenticated rebinding, cleartext data extraction, and persistent tracking via a static BLE address within 10-30 meters. Additional flaws include weak BLE peripheral spoofing checks (CVE-2026-67558), missing rate limiting enabling brute force (CVE-2026-66340), session tokens leaked via GET parameters in WebView contexts (CVE-2026-66832), and unattested firmware version reporting (CVE-2026-64934) that can suppress security update prompts. These are consumer/medical IoT and mobile app vulnerabilities with no direct AI agent tooling exposure; however, organizations building health-data RAG pipelines or agent-based health assistants that ingest Mira API data or session tokens could inadvertently process compromised or forged health records, or leak exposed API/session credentials into agent context if integrated without validation.

Affected Systems

Mira Monitor Firmware v1.7.1.47 (build 01070147); Mira Android App v4.5.15.4. Fixed in Firmware v01.07.01.53 and Mira App iOS v3.5.18 / Android v4.5.18.

Indicators of Compromise

  • No specific file hashes, IPs, or domains provided — vulnerability disclosure without known active exploitation.

Remediation Steps

  1. 1

    Update Mira Android App

    Update to Mira Android App version 4.5.18 (or iOS v3.5.18) from official app stores.

  2. 2

    Update Device Firmware

    Connect the Mira Hormone Monitor device to the updated app to automatically apply firmware v01.07.01.53.

  3. 3

    Review Account Activity

    Users should check account access logs and reset passwords given the weak authentication and brute-force vulnerabilities found in the cloud login endpoint.

  4. 4

    Limit BLE Exposure

    Avoid pairing or leaving the device in discoverable BLE mode in public/unsecured environments given the 10-30 meter unauthenticated attack range.

  5. 5

    Network Segmentation

    Follow CISA ICS recommended practices: isolate control system networks from business/internet-facing networks and use VPNs for remote access where applicable.

CVE / Advisory IDs

CVE-2026-66875CVE-2026-66098CVE-2026-67558CVE-2026-67568CVE-2026-68067CVE-2026-66340CVE-2026-64934CVE-2026-66832

Industries Most Exposed

Healthcare and Public HealthConsumer IoTMedical Devices

Sources

Respond to this threat

Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.