Executive brief
The Mira cloud API, which manages hormone monitoring data and fertility tracking for thousands of users worldwide, contains a critical authentication flaw in its login endpoint. The flaw allows attackers to gain unauthorized access to any user account by simply providing a valid email address and any password string, bypassing all password verification. Once logged in, attackers can view private health records, modify fertility and hormone data, and change account settings.
Technical details
The vulnerability is an authentication bypass in the Mira cloud API login endpoint. The vulnerable component accepts any format-valid string as a password and returns a valid session token for the account associated with the supplied email address, completely bypassing password verification. This is a missing authentication control (CWE-306) that allows unauthenticated attackers on the network to assume control of any account. The attack requires only knowledge of a valid email address and network access to the cloud API; no user interaction or prior authentication is needed. An attacker can immediately obtain a live active session token and use it to access and modify sensitive health data. Patches are available in Mira Monitor Firmware v01.07.01.53 and Mira Android App v4.5.18 (iOS) / v4.5.18 (Android).
Affected products
- Quanovate Tech Inc. Mira Monitor Firmware 1.7.1.47
- Quanovate Tech Inc. Mira Android App 4.5.15.4
Timeline
- 2026-08-11: disclosed: CISA advisory ICSMA-26-223-01 published
- 2026-08-11: patched: Patches available: Mira Monitor Firmware v01.07.01.53, iOS v3.5.18, Android v4.5.18