VYPR

Mira cloud API

by Mira

CVEs (2)

  • CVE-2026-68067CriAug 11, 2026
    risk 0.64cvss 9.8epss 0.01

    The login endpoint on the Mira cloud API accepts any format-valid string in the password field and returns a live active session token for the account matching the supplied email address. An attacker could use an email address to control cloud accounts and access hormone record…

  • CVE-2026-64934MedAug 11, 2026
    risk 0.28cvss 4.3epss 0.00

    The Mira cloud API accepts the firmware version reported by the companion app as authoritative for a given device, without independently attesting the version from the device itself. An authenticated attacker could submit arbitrary firmware version strings for their own device,…