CVE-2026-66832
When the Mira Android app opens in-app WebView content (e.g., shop redirect flows), the user's live session token is appended to the URL as a query string parameter, and a persistent user identifier is included in the WebView's User-Agent header. Both are then transmitted to third-party web properties, referrer logs, and any JavaScript running in the WebView context.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.9
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
- EPSS probability
- 0.26%
- CWE
- CWE-598
- Published
- 2026-08-11
- Last modified
- 2026-08-12
Affected products
- Quanovate Tech Inc. (operating as Mira / Mira Care) Mira Firmware
- Quanovate Tech Inc. (operating as Mira / Mira Care) Mira Firmware
- Quanovate Tech Inc. (operating as Mira / Mira Care) Mira Android App
- Quanovate Tech Inc. (operating as Mira / Mira Care) Mira Android App
Weakness type
Related vulnerabilities
- CVE-2026-88897 — Flextype CMS through 1.0.0-alpha.3 API Token Exposure via Query String
- CVE-2026-61614 — SolidInvoice's long-lived API tokens accepted as URL query parameters, exposing credentials in server logs and browser history
- CVE-2026-82181 — Le-yan|Medical Practice Management System - Sensitive Data in URL
- CVE-2026-76179 — Ebyte NA111-M Use of GET Request Method With Sensitive Query Strings
- CVE-2026-63408 — Grav API Plugin: JWT Access Token Accepted via `?token=` URL Query Parameter
- CVE-2026-74880 — openssl_encrypt before 1.4.0 Token Leakage via Query Parameters
- CVE-2026-14838 — Session Token Exposure in URL Leading to Account Takeover in Bilin Software's HUMANIST Digital Human Resources
- CVE-2026-47768 — nebula-mesh: Newly-minted operator API key exposed in redirect URL (Referer, history, proxy logs)