VYPR
advisoryPublished Jul 23, 2026· 1 source

Johnson Controls XAAP Android App Vulnerable to Cleartext Data Storage

A cleartext storage vulnerability in Johnson Controls' XAAP Android application could allow attackers with physical device access to steal sensitive information.

Johnson Controls has issued a security advisory detailing a cleartext storage vulnerability affecting its XAAP Android application. The flaw, identified as CVE-2026-34490, allows an attacker with physical access to a compromised device to read sensitive application data that is stored locally without encryption.

The vulnerability resides within the Fire Solutions Android application, where application data is written to the device's storage in plaintext. While exploitation requires physical access and the compromise of the device through a separate, unrelated vulnerability, the impact is significant. An attacker could potentially gain access to confidential information stored by the application.

This vulnerability is not remotely exploitable and is confined to the local device environment. However, given the critical infrastructure sectors where Johnson Controls products are deployed, including Critical Manufacturing, the potential for data theft warrants attention. The affected product is Johnson Controls XAAP Android, specifically versions prior to 1.53.

Johnson Controls recommends that users update the XAAP Android application to version 1.53 or later, which addresses this vulnerability. In addition to patching, the company advises implementing several mitigation strategies to further secure devices. These include restricting physical access to devices running the XAAP Android application, ensuring devices are hardened with up-to-date Android OS versions, enabling device encryption, and implementing screen lock protections.

Further mitigation recommendations from Johnson Controls include the implementation of a Mobile Device Management (MDM) solution. An MDM can enforce security policies such as encryption requirements, application whitelisting, and remote wipe capabilities. The company also strongly advises against rooting or jailbreaking devices used in production environments, as this can weaken the operating system's built-in security controls that protect local application data.

The Common Vulnerability Scoring System (CVSS) v3.1 base score for CVE-2026-34490 is 3.3 (LOW), with a vector string of CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N. The CVSS v4.0 score is 4.8 (MEDIUM), with a vector string of CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N. These scores reflect the low attack complexity and the requirement for local access.

CISA echoes these recommendations, urging organizations to minimize network exposure for all control system devices, ensure they are not accessible from the internet, and locate them behind firewalls. When remote access is necessary, secure methods like VPNs should be employed. CISA also emphasizes the importance of performing proper impact analysis and risk assessment before deploying any defensive measures.

No known public exploitation specifically targeting this vulnerability has been reported to CISA at this time. The advisory was initially released on July 23, 2026, based on information provided by Johnson Controls.

Synthesized by Vypr AI