CVE-2026-67568
Received Received - Intake

Mira Android APK Sensitive Health Data Access

Vulnerability report for CVE-2026-67568, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-11

Last updated on: 2026-08-12

Assigner: ICS-CERT

Description

The distributed Mira Android APK v4.5.15.4 allows an attacker read/write access to reproductive health profiles from internet connected hosts, which could result in forgery, deletion, or destruction of health information.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-11
Last Modified
2026-08-12
Generated
2026-09-01
AI Q&A
2026-08-12
EPSS Evaluated
2026-08-30
NVD
EUVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-798 The product contains hard-coded credentials, such as a password or cryptographic key.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in the distributed Mira Android APK v4.5.15.4 allows an attacker to gain read/write access to reproductive health profiles from internet-connected hosts. This could lead to unauthorized forgery, deletion, or destruction of sensitive health information.

Detection Guidance

This vulnerability involves unauthorized read/write access to reproductive health profiles via the Mira Android APK v4.5.15.4. Detection requires checking for unauthorized network connections to the APK or unusual data access patterns. Inspect Mira app logs for suspicious activity and monitor network traffic for unexpected data transfers to/from the APK endpoint.

Impact Analysis

If exploited, this vulnerability could compromise the confidentiality, integrity, and availability of your reproductive health data. Attackers might alter or delete your health records, leading to incorrect medical decisions or privacy violations.

Compliance Impact

This vulnerability likely violates data protection regulations such as GDPR and HIPAA due to unauthorized access and potential destruction of sensitive health data. Organizations using this APK may face legal penalties and compliance failures.

Mitigation Strategies

Immediately isolate any systems running the vulnerable Mira Android APK v4.5.15.4 from the network to prevent unauthorized access. Disable or uninstall the application if it is not essential. Monitor network traffic for unusual activity related to reproductive health profile data. Ensure all sensitive health information is backed up and verify its integrity.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-67568. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart