Junglewise Threat Intelligence

CVE-2026-66340: Mira cloud authentication brute-force vulnerability

CVE-2026-66340 · Severity: medium · CVSS 5.3 · Published 2026-08-11

Technologies: Quanovate Tech Inc. Mira Android App, Quanovate Tech Inc. Mira Monitor Firmware. Vendors: Quanovate Tech Inc..

Executive brief

Mira's cloud authentication system does not implement rate limiting, IP throttling, or account lockout protections. An attacker can repeatedly submit login attempts without restriction, enabling brute-force attacks to gain unauthorized access to user accounts containing sensitive health and fertility tracking data.

Technical details

The vulnerability is an improper restriction of excessive authentication attempts (CWE-640) in Mira's cloud authentication endpoints. The authentication service lacks per-account rate limiting, per-IP request throttling, and account lockout mechanisms following repeated failed login attempts. An attacker with network access can conduct brute-force attacks against user accounts without triggering any protective countermeasures. No authentication is required to initiate login attempts. Patches are available: Mira Monitor Firmware v01.07.01.53 and Mira Android App v4.5.18.

Affected products

  • Quanovate Tech Inc. Mira Monitor Firmware 1.7.1.47
  • Quanovate Tech Inc. Mira Android App 4.5.15.4

Timeline

  • 2026-08-11: disclosed

References

Related threats