Johnson Controls XAAP Android Cleartext Storage of Sensitive Information (CVE-2026-34490)
First seen Jul 25, 2026 · Updated Jul 25, 2026 · CVSS 3.3
Johnson Controls XAAP Android application versions prior to 1.53 store application data locally in cleartext, allowing an attacker with physical device access and a separate compromise vector to read sensitive data in plaintext. Exploitation requires local device access and cannot be performed remotely over a network.
Technical Analysis
CVE-2026-34490 (CWE-312: Cleartext Storage of Sensitive Information) affects the Johnson Controls XAAP Android Fire Solutions application, which writes local application data without encryption. Exploitation requires local physical access to the device combined with a separate flaw or method to access the device's filesystem, rated CVSS v3.1 3.3 (Low) and CVSS v4.0 4.8 (Medium) due to its local attack vector and low confidentiality impact only. There is no known public exploitation and no remote attack path exists. This is a mobile/OT device vulnerability with no direct connection to AI agent, LLM, or RAG infrastructure, and no plausible agent-relevant impact has been identified.
Affected Systems
Johnson Controls XAAP Android (Fire Solutions Android application) versions prior to 1.53, deployed worldwide primarily in Critical Manufacturing sector environments.
Indicators of Compromise
- No specific IOCs published; this is a vulnerability advisory rather than an active exploitation campaign.
Remediation Steps
- 1
Update Application
Update Johnson Controls XAAP Android application to version 1.53 or later, which contains the fix for this vulnerability.
- 2
Restrict Physical Access
Limit and control physical access to devices running the XAAP Android application.
- 3
Harden Devices
Ensure devices run up-to-date Android OS versions, enable device encryption, and enforce screen lock protections.
- 4
Deploy MDM
Implement a Mobile Device Management solution to enforce encryption requirements, application whitelisting, and remote wipe capabilities.
- 5
Avoid Rooting/Jailbreaking
Do not root or jailbreak devices used in production environments, as this weakens OS-level security controls protecting local application data.
- 6
Network Segmentation
Minimize network exposure of control system devices, isolate them behind firewalls from business networks, and avoid direct internet accessibility.
CVE / Advisory IDs
Industries Most Exposed
Respond to this threat
Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.