Critical severity9.8NVD Advisory· Published Aug 11, 2026· Updated Sep 1, 2026
CVE-2026-68067
CVE-2026-68067
Description
The login endpoint on the Mira cloud API accepts any format-valid string in the password field and returns a live active session token for the account matching the supplied email address. An attacker could use an email address to control cloud accounts and access hormone record information and account settings.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1Patches
Vulnerability mechanics
References
2News mentions
1- Mira Hormone Monitor, Mira Android AppCISA Alerts