Sensitive Data Exposure Vulnerability in Johnson Controls XAAP Application on Android
CVE-2026-34490
4.8MEDIUM
What is CVE-2026-34490?
The Johnson Controls XAAP Application for Android is susceptible to a vulnerability that allows cleartext storage of sensitive information. Attackers utilizing jailbroken or otherwise compromised devices could potentially retrieve sensitive data, posing significant risks to user privacy and security. It is critical that users upgrade to the latest version to mitigate this exposure.
Affected Version(s)
XAAP Application Android 0 < 1.53
