# Johnson Controls XAAP Android Stores Data Unencrypted

Published: 2026-07-23 · Severity: low · Sectors: manufacturing
Canonical: https://vorant.io/reports/b07ba294-26b2-5313-a2a9-9dfda79e01ed/johnson-controls-xaap-android-stores-data-unencrypted

> A cleartext storage flaw in Johnson Controls' XAAP Android app could let attackers with physical device access read sensitive data in plaintext.

CISA published an advisory for a vulnerability in Johnson Controls' XAAP Android application (Fire Solutions), tracked as CVE-2026-34490. The app stores application data locally on the device without encryption, meaning an attacker who already has physical access to the device—or who has compromised it through a separate, unrelated flaw—could read the stored data in plaintext. The issue is classified under CWE-312 (Cleartext Storage of Sensitive Information) and requires no network access, limiting exploitation to the local device environment.

The vulnerability affects all versions of XAAP Android prior to 1.53, deployed worldwide across the Critical Manufacturing sector. Johnson Controls has released version 1.53 to remediate the flaw and recommends additional mitigations including restricting physical device access, enforcing Android OS hardening and device encryption, deploying MDM solutions, and avoiding rooting or jailbreaking of production devices. No public exploitation of this vulnerability has been reported to CISA at this time, and the flaw cannot be exploited remotely, limiting its overall real-world urgency.

## Mentioned in this report

- Vulnerabilities: CVE-2026-34490

Source reporting: https://www.cisa.gov/news-events/ics-advisories/icsa-26-204-02

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/b07ba294-26b2-5313-a2a9-9dfda79e01ed/johnson-controls-xaap-android-stores-data-unencrypted.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
