Cleartext storage of sensitive information vulnerability in Johnson Controls XAAP Application on Android allows an attacker on a jailbroken or otherwise compromised device to Retrieve Sensitive Data.
This issue affects XAAP Application: before 1.53.
References
| Link | Resource |
|---|---|
| https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories | Vendor Advisory Mitigation |
Configurations
History
No history.
Information
Published : 2026-07-31 18:17
Updated : 2026-08-10 19:53
NVD link : CVE-2026-34490
Mitre link : CVE-2026-34490
CVE.ORG link : CVE-2026-34490
JSON object : View
Products Affected
johnsoncontrols
- xaap
CWE
CWE-312
Cleartext Storage of Sensitive Information
