All CVEs
Vulnerability intelligence

CVE-2026-68067

Quanovate Tech Inc. (operating as Mira / Mira Care) Mira Firmware CWE-1390

The login endpoint on the Mira cloud API accepts any format-valid string in the password field and returns a live active session token for the account matching the supplied email address. An attacker could use an email address to control cloud accounts and access hormone record information and account settings.

CVSS Score
9.8
Critical
EPSS — Exploit Probability
0.3%
Riskier than 24% of all CVEs · checked 2026-09-22
Exploitation
Not in CISA KEV
KEV does not include every exploited vulnerability
Remediation
unknown
Check vendor advisories
NVD entry PoC / advisory

1 article across 1 outlet · first covered Aug 14, 2026 · latest Aug 14, 2026

Coverage timeline