CVE-2026-67558 HIGH

CVE-2026-67558: Mira Hormone Monitor, Mira Android App Authentication bypass by spoofing

Vendor Quanovate Tech Inc. (Operating As Mira / Mira Care)
Product Mira Firmware
Weakness CWE-290
Published August 11, 2026
Last update August 11, 2026

CVSS base score

8.2/10
Attack vector Adjacent
Attack complexity Low
Privileges required None
User interaction
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:A/VC:H/VI:L/VA:N/SC:H/SI:L/SA:N

What the vulnerability does

01Description

The Mira Android companion app v4.5.15.4 identifies the paired Mira hormone analyzer by performing a substring match against the BLE advertisement name only, with no cryptographic peripheral authentication, MAC allowlist, or bonded-identity check. An attacker could capture live session token information and inject forged hormone measurements into the victim's cloud record and clinical trend view.

Key dates

02Disclosure timeline

August 11, 2026 CVE published

Related vulnerabilities

04Related CVE