CVE-2026-66340: Quanovate Tech Inc. Operating As Mira / Mira Care Mira Android App
Medium severity, CVSS 5.3. EPSS: 0.4% chance of exploitation in the next 30 days.
The Mira cloud authentication endpoints do not enforce per-account rate limiting, per-IP throttling, or account lockout after repeated failed login attempts. An attacker can use brute-force methods to obtain gain access to user accounts.
Affected products
- Quanovate Tech Inc. Operating As Mira / Mira Care Mira Android App: version 4.5.15.4 only
- Quanovate Tech Inc. Operating As Mira / Mira Care Mira Firmware: version 1.7.1.47 only
Published 2026-08-11. Last modified 2026-09-01.