The login endpoint on the Mira cloud API accepts any format-valid string in the password field and returns a live active session token for the account matching the supplied email address. An attacker could use an email address to control cloud accounts and access hormone record information and account settings.
Metrics
Affected Vendors & Products
References
History
Tue, 11 Aug 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The login endpoint on the Mira cloud API accepts any format-valid string in the password field and returns a live active session token for the account matching the supplied email address. An attacker could use an email address to control cloud accounts and access hormone record information and account settings. | |
| Title | Mira Hormone Monitor, Mira Android App Weak Authentication | |
| Weaknesses | CWE-1390 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2026-08-11T21:23:05.640Z
Reserved: 2026-08-03T16:54:56.485Z
Link: CVE-2026-68067
No data.
Status : Received
Published: 2026-08-11T22:18:55.017
Modified: 2026-08-11T22:18:55.017
Link: CVE-2026-68067
No data.
OpenCVE Enrichment
No data.