CVE-2026-34490: XAAP Android Data Stored in Unencrypted Database
Published Jul 31, 2026
·Updated
Cleartext storage of sensitive information vulnerability in Johnson Controls XAAP Application on Android allows an attacker on a jailbroken or otherwise compromised device to Retrieve Sensitive Data.
This issue affects XAAP Application: before 1.53.
Affected Software
2 affected components
Johnson Controls XAAP Application (Android)<1.53
Johnsoncontrols Xaap Android<1.53
Event History
Jul 31, 2026
CVE Published
via MITRE·05:17 PM
Data Sourced
via MITRE·05:17 PM
DescriptionWeakness
Data Sourced
via NVD·06:17 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
Who is realistically exposed to this issue?
Users of the Johnson Controls XAAP Application on Android versions before 1.53 are exposed when the app runs on a jailbroken or otherwise compromised device.
2
What does an attacker need to retrieve the affected data?
The attacker needs access to a jailbroken or otherwise compromised Android device that has the affected application installed. The issue is locally exploitable and does not require user interaction.
3
What is the remediation?
Update the Johnson Controls XAAP Application to version 1.53 or later. Versions before 1.53 are affected.