๐Ÿ” CVE Alert

CVE-2026-34490

UNKNOWN 0.0

XAAP Android Data Stored in Unencrypted Database

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Cleartext storage of sensitive information vulnerability in Johnson Controls XAAP Application on Android allows an attacker on a jailbroken or otherwise compromised device to Retrieve Sensitive Data. This issue affects XAAP Application: before 1.53.

CWE CWE-312
Vendor johnson controls
Product xaap application
Published Jul 31, 2026
Last Updated Jul 31, 2026
Stay Ahead of the Next One

Get instant alerts for johnson controls xaap application

Be the first to know when new unknown vulnerabilities affecting johnson controls xaap application are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Johnson Controls / XAAP Application
0 < 1.53

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
johnsoncontrols.com: https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories