Description
Cleartext storage of sensitive information vulnerability in Johnson Controls XAAP Application on Android allows an attacker on a jailbroken or otherwise compromised device to Retrieve Sensitive Data.
This issue affects XAAP Application: before 1.53.
This issue affects XAAP Application: before 1.53.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Fri, 31 Jul 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Cleartext storage of sensitive information vulnerability in Johnson Controls XAAP Application on Android allows an attacker on a jailbroken or otherwise compromised device to Retrieve Sensitive Data. This issue affects XAAP Application: before 1.53. | |
| Title | XAAP Android Data Stored in Unencrypted Database | |
| First Time appeared |
Johnson Controls
Johnson Controls xaap Application |
|
| Weaknesses | CWE-312 | |
| CPEs | cpe:2.3:a:johnson_controls:xaap_application:*:*:android:*:*:*:*:* | |
| Vendors & Products |
Johnson Controls
Johnson Controls xaap Application |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: jci
Published:
Updated: 2026-07-31T17:17:33.651Z
Reserved: 2026-03-30T08:25:11.763Z
Link: CVE-2026-34490
No data.
No data.
No data.
OpenCVE Enrichment
No data.
Weaknesses