Description
Cleartext storage of sensitive information vulnerability in Johnson Controls XAAP Application on Android allows an attacker on a jailbroken or otherwise compromised device to Retrieve Sensitive Data.

This issue affects XAAP Application: before 1.53.
Published: 2026-07-31
Score: 4.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a cleartext storage of sensitive data in the XAAP Application's local database on Android. The data is stored without encryption, allowing an attacker who gains local access to the device—such as through a jailbreak or other compromise—to retrieve confidential information. This can lead to privacy violations and potential misuse of the data. The weakness is classified as CWE‑312, Plaintext Storage of Sensitive Information.

Affected Systems

Customers running Johnson Controls XAAP Application on Android with a version earlier than 1.53 are affected. The vulnerability arises in the application's handling of local data storage. The affected product is the XAAP Application published by Johnson Controls for Android devices.

Risk and Exploitability

The CVSS score of 4.8 indicates a moderate impact, and the EPSS score of less than 1 % suggests a low probability of exploitation. The vulnerability is not present in the CISA KEV catalog. Exploitation requires local device compromise; an adversary would need a jailbroken or otherwise compromised Android device to read the unencrypted database. While the risk to remote attackers is limited, operators should treat it as a moderate information‑disclosure risk that could be leveraged to obtain protected data.

Generated by OpenCVE AI on August 2, 2026 at 04:03 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the XAAP Application to version 1.53 or later.
  • Avoid using the application on jailbroken or otherwise compromised Android devices.
  • If immediate upgrade is not possible, restrict access to the device's local storage and consider encrypting the database or moving sensitive data to a secure remote service.

Generated by OpenCVE AI on August 2, 2026 at 04:03 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Johnsoncontrols
Johnsoncontrols xaap Application
Vendors & Products Johnsoncontrols
Johnsoncontrols xaap Application

Fri, 31 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 31 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Description Cleartext storage of sensitive information vulnerability in Johnson Controls XAAP Application on Android allows an attacker on a jailbroken or otherwise compromised device to Retrieve Sensitive Data. This issue affects XAAP Application: before 1.53.
Title XAAP Android Data Stored in Unencrypted Database
First Time appeared Johnson Controls
Johnson Controls xaap Application
Weaknesses CWE-312
CPEs cpe:2.3:a:johnson_controls:xaap_application:*:*:android:*:*:*:*:*
Vendors & Products Johnson Controls
Johnson Controls xaap Application
References
Metrics cvssV4_0

{'score': 4.8, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Johnson Controls Xaap Application
Johnsoncontrols Xaap Xaap Application
cve-icon MITRE

Status: PUBLISHED

Assigner: jci

Published:

Updated: 2026-07-31T17:38:49.752Z

Reserved: 2026-03-30T08:25:11.763Z

Link: CVE-2026-34490

cve-icon Vulnrichment

Updated: 2026-07-31T17:38:41.821Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-31T18:17:14.150

Modified: 2026-08-10T19:53:40.270

Link: CVE-2026-34490

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T20:32:31Z

Weaknesses
  • CWE-312

    Cleartext Storage of Sensitive Information