NONE · 0

CVE-2026-34490

Cleartext storage of sensitive information vulnerability in Johnson Controls XAAP Application on Android allows an attacker on a jailbroken or otherwise compromised device to Retrieve Sensitive Data. ...

Vulnerability Description

Cleartext storage of sensitive information vulnerability in Johnson Controls XAAP Application on Android allows an attacker on a jailbroken or otherwise compromised device to Retrieve Sensitive Data. This issue affects XAAP Application: before 1.53.

Related Weaknesses (CWE)

References

FAQ

What is CVE-2026-34490?

CVE-2026-34490 is a documented vulnerability. Cleartext storage of sensitive information vulnerability in Johnson Controls XAAP Application on Android allows an attacker on a jailbroken or otherwise compromised device to Retrieve Sensitive Data. ...

How severe is CVE-2026-34490?

CVSS scoring is not yet available for CVE-2026-34490. Check NVD for updates.

Is there a patch for CVE-2026-34490?

Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.