All intelligence
// vulnerability record
cached · NVD via COSMOS syncCVE-2026-66340
MEDIUMpublished 2026-08-11 22:18 UTC · 1 day ago · modified 2026-08-12 14:18 UTC
6.9
CVSS / 10
// description
The Mira cloud authentication endpoints do not enforce per-account rate limiting, per-IP throttling, or account lockout after repeated failed login attempts. An attacker can use brute-force methods to obtain gain access to user accounts.
// weaknesses (CWE)
- CWE-307