Johnson Controls XAAP Android
View CSAF Summary Successful exploitation of this vulnerability could result in an attacker obtaining confidential information from the device. The following versions of Johnson Controls XAAP Android are affected: XAAP Android <1.53 CVSS Vendor Equipment Vulnerabilities v3 3.3 Johnson Controls Johnson Controls XAAP Android Cleartext Storage of Sensitive Information Background Critical Infrastructure Sectors: Critical Manufacturing Countries/Areas Deployed: Worldwide Company Headquarters Location: Ireland Vulnerabilities Expand All + CVE-2026-34490 A cleartext storage weakness exists in the Fire Solutions Android application, which stores application data locally on the device without encryption. An attacker with physical access to the device and one able to compromise the device through a separate, unrelated flaw, could potentially read this data in plaintext. Exploitation does not require network access and is limited to the local device environment. View CVE Details Affected Products Johnson Controls XAAP Android Vendor: Johnson Controls Product Version: Johnson Controls XAAP Android: <1.53 Product Status: known_affected Remediations Vendor fix Johnson Controls recommends users update the XAAP Android application to version 1.53 or later, which contains the fix for this vulnerability. Mitigation Johnson Controls recommends users restrict physical access to devices running the XAAP Android application. Mitigation Johnson Controls recommends users ensure devices are hardened with up-to-date Android OS versions, device encryption enabled, and screen lock protections in place. Mitigation Johnson Controls recommends users implement a Mobile Device Management (MDM) solution to enforce security policies, including encryption requirements, application whitelisting, and remote wipe capabilities. Mitigation Johnson Controls recommends users Avoid rooting or jailbreaking devices used in production environments, as this weakens OS-level security controls that help protect loc
CSIRTS triage
- What
- Cleartext storage of sensitive information could allow attackers to obtain confidential data.
- Who is affected
- Users of XAAP Android versions prior to 1.53.
- Urgency
- Remediation is critical to protect sensitive information.
- Action
- Update to version 1.53 or later.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch XAAP Android
Get an email when a new XAAP Android advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://www.cisa.gov/news-events/ics-advisories/icsa-26-204-02
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-34490 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
Recent advisories for Johnson Controls XAAP
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
More from CISA Cybersecurity Advisories
- criticalWatchfire Controller Software2026-07-30
- criticalMZ Automation GmbH libiec618502026-07-30
- criticalToptech Systems RCU II+ and Multiload II+2026-07-30
- criticalNASA Core Flight System (cFS) Health & Safety (HS) Application2026-07-30
- criticalMikroTik RouterOS2026-07-30