VYPR
advisoryPublished Aug 11, 2026· 1 source

CISA Warns of Multiple Vulnerabilities in Mira Hormone Monitor and App

CISA has issued an alert detailing critical vulnerabilities in the Mira Hormone Monitor and its accompanying Android application, potentially exposing sensitive health data and allowing unauthorized control.

CISA has issued a joint cybersecurity advisory detailing multiple vulnerabilities affecting the Mira Hormone Monitor and its associated Android application. These flaws, identified by Quanovate Tech Inc., which operates as Mira and Mira Care, could allow attackers to access sensitive health information, gain control of user accounts, and disrupt the device's functionality.

The vulnerabilities primarily stem from missing authentication for critical functions, authentication bypass by spoofing, use of hard-coded credentials, weak authentication mechanisms, and improper restriction of excessive authentication attempts. These weaknesses collectively enable attackers to perform a range of malicious actions.

Specifically, CVE-2026-66875 allows a remote, unauthenticated attacker within Bluetooth Low Energy (BLE) range to rebind the device to an attacker-controlled account, extract stored hormone measurements in cleartext, cause a denial-of-service, and passively track users via a static BLE address. This poses a significant privacy risk, as intimate health data could be exfiltrated.

Another critical vulnerability, CVE-2026-66098, allows any BLE central to reboot the Mira hormone monitor into bootloader mode without authentication. This could lead to a denial-of-service condition, disrupting the device's primary function of ovulation tracking and fertility monitoring.

Furthermore, CVE-2026-67558 highlights a weakness in the Mira Android app's pairing mechanism. By performing only a substring match against the BLE advertisement name, the app fails to implement cryptographic authentication or check bonded identities. This allows an attacker to capture live session token information and inject forged hormone measurements into a victim's cloud record.

Additional vulnerabilities, including CVE-2026-67568 and CVE-2026-68067, further expose users to risks such as unauthorized read/write access to reproductive health profiles from internet-connected hosts, potentially leading to forgery, deletion, or destruction of health information. The full list of affected CVEs includes CVE-2026-66875, CVE-2026-66098, CVE-2026-67558, CVE-2026-67568, CVE-2026-68067, CVE-2026-66340, CVE-2026-64934, and CVE-2026-66832.

The affected products are Mira Monitor Firmware version 1.7.1.47 and Mira Android App version 4.5.15.4. The CVSS scores for these vulnerabilities range from medium to critical, with the highest base score being 9.8 (CVSS v3.1) and 9.3 (CVSS v4.0), indicating a significant risk to users.

Quanovate Tech Inc. has released updates to mitigate these risks. Users are advised to update the Mira app to the latest version (iOS v3.5.18 / Android v4.5.18). Firmware version v01.07.01.53 is updated automatically via the app when the device is connected. No additional user action is required beyond updating the app.

Synthesized by Vypr AI