CRITICALVulnerability

CVE-2026-68067

The login endpoint on the Mira cloud API accepts any format-valid string in the password field and returns a live active session token for the account matching the supplied email address. An attacker could use an email address to control cloud accounts and access hormone record information and account settings.

Properties

severity
CRITICAL
score
9.8
cve_id
CVE-2026-68067
vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
published_at
2026-08-11T22:18:55.017
last_modified
2026-09-01T21:16:58.690

Related Entities (2)

DESCRIBED_BY (1)

[Source]NVD

HAS_WEAKNESS (1)

[Weakness]Weak Authentication

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-68067 — Ninja Signal Threat Intelligence | Ninja Signal