AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-64934

MEDIUM · CVSS 4.3 EPSS 0.18% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-11 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

The Mira cloud API is vulnerable due to its reliance on the firmware version reported by the companion app, allowing authenticated attackers to submit arbitrary version strings for their devices. This could enable them to bypass vendor analytics, suppress security update notifications, and distort patch adoption metrics. Organizations using the Mira platform should prioritize addressing this vulnerability to maintain the integrity of their device management and security update processes.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-64934
Severity
MEDIUM
CVSS
4.3
EPSS
0.18%

Original NVD Description

The Mira cloud API accepts the firmware version reported by the companion app as authoritative for a given device, without independently attesting the version from the device itself. An authenticated attacker could submit arbitrary firmware version strings for their own device, allowing them to evade vendor-side vulnerable-fleet analytics, suppress security update prompts to the user, and misrepresent patch-adoption metrics.