CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-34490

criticalcovered by 2 sourcesfirst seen 2026-07-23
View CSAF Summary Successful exploitation of this vulnerability could result in an attacker obtaining confidential information from the device. The following versions of Johnson Controls XAAP Android are affected: XAAP Android <1.53 CVSS Vendor Equipment Vulnerabilities v3 3.3 Johnson Controls Johnson Controls XAAP Android Cleartext Storage of Sensitive Information Background Critical Infrastructure Sectors: Critical Manufacturing Countries/Areas Deployed: Worldwide Company Headquarters Location: Ireland Vulnerabilities Expand All + CVE-2026-34490 A cleartext storage weakness exists in the Fire Solutions Android application, which stores application data locally on the device without encryption. An attacker with physical access to the device and one able to compromise the device through a separate, unrelated flaw, could potentially read this data in plaintext. Exploitation does not require network access and is limited to the local device environment. View CVE Details Affected Products Johnson Controls XAAP Android Vendor: Johnson Controls Product Version: Johnson Controls XAAP Android: <1.53 Product Status: known_affected Remediations Vendor fix Johnson Controls recommends users update the XAAP Android application to version 1.53 or later, which contains the fix for this vulnerability. Mitigation Johnson Controls recommends users restrict physical access to devices running the XAAP Android application. Mitigation Johnson Controls recommends users ensure devices are hardened with up-to-date Android OS versions, device encryption enabled, and screen lock protections in place. Mitigation Johnson Controls recommends users implement a Mobile Device Management (MDM) solution to enforce security policies, including encryption requirements, application whitelisting, and remote wipe capabilities. Mitigation Johnson Controls recommends users Avoid rooting or jailbreaking devices used in production environments, as this weakens OS-level security controls that help protect loc

CSIRTS triage

What
Cleartext storage of sensitive information could allow attackers to obtain confidential data.
Who is affected
Users of XAAP Android versions prior to 1.53.
Urgency
Remediation is critical to protect sensitive information.
Action
Update to version 1.53 or later.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2026-34490

Get an email if CVE-2026-34490 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Advisory coverage (2)

External references

NVD record for CVE-2026-34490

CVE.org record

Embed the live status

CVE-2026-34490 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-34490 status](https://www.csirts.com/badge/CVE-2026-34490)](https://www.csirts.com/cve/CVE-2026-34490)