CVE-2026-66832
Last modified
CVE-2026-66832 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. When the Mira Android app opens in-app WebView content (e.g., shop redirect flows), the user's live session token is appended to the URL as a query string parameter, and a persistent user identifier is included in the WebView's User-Agent header. Both are then transmitted to third-party web properties, referrer logs, and any JavaScript running in the WebView context.. EPSS estimates a 0.26% chance of exploitation in the next 30 days.
Description
When the Mira Android app opens in-app WebView content (e.g., shop redirect flows), the user's live session token is appended to the URL as a query string parameter, and a persistent user identifier is included in the WebView's User-Agent header. Both are then transmitted to third-party web properties, referrer logs, and any JavaScript running in the WebView context.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Quanovate Tech Inc. (operating as Mira / Mira Care) | Mira Firmware | 1.7.1.47 |
| Quanovate Tech Inc. (operating as Mira / Mira Care) | Mira Android App | 4.5.15.4 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-66832?
How severe is CVE-2026-66832?
How do I fix CVE-2026-66832?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-6682In FatFS R0.16 and earlier contains a FAT32 integer overflow…7.6
- CVE-2026-66820Improper neutralization of special elements used in an sql c…8.8
- CVE-2026-66824A stored cross-site scripting vulnerability existed in the c…9.2
- CVE-2026-66825Pivotick contains a cross-site scripting vulnerability in th…6.9
- CVE-2026-66829URL Redirection to Untrusted Site ('Open Redirect') vulnerab…6.1
- CVE-2026-6683FatFs R0.16 and earlier contains a divide-by-zero in exFAT s…4.6
- CVE-2026-66835Path Equivalence vulnerability in Erlang/OTP inets httpd all…8.2
- CVE-2026-66838Improper Neutralization of Special Elements used in an SQL C…8.2
- CVE-2026-66839NetKids iMark, provided by Integrated Systems Technologies, …8.4
- CVE-2026-6684FatFs prior to R0.16 that use GPT scanning with 'FF_LBA64 = …4.6
- CVE-2026-66840XING CPTrans-ME-X contains an Exposure of Sensitive System I…8.7
- CVE-2026-66842BIG-IP has a vulnerability where an authenticated user of an…8.8
Are you affected by CVE-2026-66832?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
