Medium severity5.5NVD Advisory· Published Jul 31, 2026· Updated Aug 10, 2026
CVE-2026-34490
CVE-2026-34490
Description
Cleartext storage of sensitive information vulnerability in Johnson Controls XAAP Application on Android allows an attacker on a jailbroken or otherwise compromised device to Retrieve Sensitive Data.
This issue affects XAAP Application: before 1.53.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- Range: <1.53
Patches
Vulnerability mechanics
References
1- www.johnsoncontrols.com/trust-center/cybersecurity/security-advisoriesnvdVendor AdvisoryMitigation
News mentions
1- Johnson Controls XAAP AndroidCISA ICS Advisories