CVE-2026-68067Disclosure

LOWCVSS 9.3 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The login endpoint on the Mira cloud API accepts any format-valid string in the password field and returns a live active session token for the account matching the supplied email address. An attacker could use an email address to control cloud accounts and access hormone record information and account settings.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-1390

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-08-14: 1Technical Details · 2026-08-14: 108-14
Signal classification1 categories
Disclosure
1100.0%
Referenced assets1 URL
By indicator
Full discourse1 post
  • Daily CyberSecurity@Daily_CyberSec
    Disclosure

    CVE-2026-68067 (CVSS 9.8) lets attackers control user accounts on the Mira Hormone Monitor by bypassing the cloud login. Eight flaws total. #MiraMonitor #CVE202668067 #MedicalDevice #AccountTakeover #CISA #IoTSecurity #Cybersecurity https://securityonline.info/mira-hormone-monitor-account-takeover/

    Post summary

    A new CVE-2026-68067 with CVSS 9.8 has been announced, allowing attackers to take over user accounts on the Mira Hormone Monitor by bypassing cloud login. No evidence of active exploitation or patching information is provided.

    00000431
    12.7K followersView on X

Explore more