This issue affects XAAP Application: before 1.53.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 31 Jul 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 31 Jul 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Cleartext storage of sensitive information vulnerability in Johnson Controls XAAP Application on Android allows an attacker on a jailbroken or otherwise compromised device to Retrieve Sensitive Data. This issue affects XAAP Application: before 1.53. | |
| Title | XAAP Android Data Stored in Unencrypted Database | |
| First Time appeared |
Johnson Controls
Johnson Controls xaap Application |
|
| Weaknesses | CWE-312 | |
| CPEs | cpe:2.3:a:johnson_controls:xaap_application:*:*:android:*:*:*:*:* | |
| Vendors & Products |
Johnson Controls
Johnson Controls xaap Application |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: jci
Published:
Updated: 2026-07-31T17:38:49.752Z
Reserved: 2026-03-30T08:25:11.763Z
Link: CVE-2026-34490
Updated: 2026-07-31T17:38:41.821Z
No data.
No data.
OpenCVE Enrichment
No data.
-
CWE-312
Cleartext Storage of Sensitive Information