Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Users should update the Mira app to the latest version iOS v3.5.18 / Android v4.5.18. Firmware v01.07.01.53 is updated via the app when the device is connected. No additional action is required.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 11 Aug 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | When the Mira Android app opens in-app WebView content (e.g., shop redirect flows), the user's live session token is appended to the URL as a query string parameter, and a persistent user identifier is included in the WebView's User-Agent header. Both are then transmitted to third-party web properties, referrer logs, and any JavaScript running in the WebView context. | |
| Title | Mira Hormone Monitor, Mira Android App Use of GET request method with sensitive query strings | |
| Weaknesses | CWE-598 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2026-08-11T20:49:56.584Z
Reserved: 2026-08-03T16:54:56.493Z
Link: CVE-2026-66832
No data.
Status : Received
Published: 2026-08-11T21:17:49.713
Modified: 2026-08-11T21:17:49.713
Link: CVE-2026-66832
No data.
OpenCVE Enrichment
No data.