CVE-2026-66832
Deferred
Deferred - Pending Action
BaseFortify
Vulnerability report for CVE-2026-66832, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-08-11
Last updated on: 2026-09-01
Assigner: ICS-CERT
Description
Description
When the Mira Android app opens in-app WebView content (e.g., shop redirect flows), the user's live session token is appended to the URL as a query string parameter, and a persistent user identifier is included in the WebView's User-Agent header. Both are then transmitted to third-party web properties, referrer logs, and any JavaScript running in the WebView context.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| Quanovate | Tech | Inc. (operating as Mira / Mira Care) Mira Firmware 1.7.1.47 |
| Quanovate | Tech | Inc. (operating as Mira / Mira Care) Mira Android App 4.5.15.4 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-598 | The web application uses the HTTP GET method to process a request and includes sensitive information in the query string of that request. |