CVE-2026-34490

Summary

Cleartext storage of sensitive information vulnerability in Johnson Controls XAAP Application on Android allows an attacker on a jailbroken or otherwise compromised device to Retrieve Sensitive Data.

This issue affects XAAP Application: before 1.53.

Affected Software

VendorProductVersion RangeStatus
Johnson ControlsXAAP Application0 < 1.53affected

Weaknesses

  • CWE-312: CWE-312 Cleartext storage of sensitive information

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References