PT-2026-8026 · Unknown · Adb-Explorer+1

Blankshiro

·

Publicado

2026-02-13

·

Atualizado

2026-02-18

·

CVE-2026-26208

CVSS v3.1

7.8

Alta

VetorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ADB Explorer versions prior to Beta 0.9.26020
Description ADB Explorer, a fluent UI for ADB on Windows, contains a flaw due to Insecure Deserialization, potentially leading to Remote Code Execution. The application deserializes the App.txt settings file using Newtonsoft.Json with TypeNameHandling set to Objects. An attacker can provide a specially crafted JSON file containing a gadget chain, such as ObjectDataProvider, to execute arbitrary code when the application launches and saves its settings.
Recommendations Update to Beta 0.9.26020 or later.

Exploit

Correção

RCE

Deserialization of Untrusted Data

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-26208
GHSA-49QX-WPXJ-P4MH

Produtos afetados

Adb-Explorer
Newtonsoft.Json