HomeIntelligenceBrief
VULNERABILITY BRIEF🟢 Low Vulnerability

Cleartext Storage Vulnerability (CVE-2026-34490) in Johnson Controls XAAP Android Risks Confidential Data

A vulnerability (CVE-2026-34490) in Johnson Controls’ XAAP Android application stores data in cleartext, enabling an attacker with physical access or a separate exploit to read sensitive information. The flaw affects all versions prior to 1.53 and carries a CVSS v3 score of 3.3. For organizations subject to SOC 2, the issue highlights gaps in encryption‑at‑rest controls and the need for continuous evidence of data protection.

LiveThreat™ Intelligence · 📅 July 24, 2026· 📰 cisa.gov
🟢
Severity
Low
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
1 sector(s)
Actions
3 recommended
📰
Source
cisa.gov

Cleartext Storage Vulnerability (CVE‑2026‑34490) in Johnson Controls XAAP Android Risks Confidential Data

What It Is — A cleartext storage weakness in the Fire Solutions Android application (Johnson Controls XAAP Android) allows data saved locally on the device to be read in plaintext. The flaw is tracked as CVE‑2026‑34490.

Exploitability — Exploitation requires physical access to the device or a separate, unrelated compromise; no network access is needed. CVSS v3 base score 3.3 (Low).

Affected Products — Johnson Controls XAAP Android < 1.53 (all prior releases).

Why It Matters for Compliance & Audit Readiness

  • SOC 2 Security & Confidentiality criteria mandate encryption of data at rest; cleartext storage directly violates these controls.
  • Mapping this gap to the SOC 2 control matrix provides concrete audit evidence that the organization has identified and remediated a control deficiency.
  • Continuous monitoring of patch levels across all XAAP devices creates a defensible audit trail and demonstrates due‑diligence to enterprise customers.

Recommended Actions

  • Deploy Johnson Controls’ patch – upgrade XAAP Android to version 1.53 or later immediately.
  • Enforce device‑level encryption and configure the application to store all data using strong encryption (e.g., AES‑256).
  • Record the remediation in your SOC 2 control inventory and capture compliance evidence (patch version, encryption settings) for audit reviews.

Source: CISA Advisory – ICSA‑26‑204‑02

📰 Original Source
https://www.cisa.gov/news-events/ics-advisories/icsa-26-204-02

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Every gap like this maps to a control you can evidence.

The Verisq AI Trust Operations platform maps incidents to your control framework and collects the evidence continuously — so your Trust Center shows proof, not promises, when a buyer or auditor asks.

Explore the Verisq AI Trust Operations platform →