PT-2026-8026 · Unknown · Adb-Explorer+1
Blankshiro
·
Published
2026-02-13
·
Updated
2026-02-18
·
CVE-2026-26208
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
ADB Explorer versions prior to Beta 0.9.26020
Description
ADB Explorer, a fluent UI for ADB on Windows, contains a flaw due to Insecure Deserialization, potentially leading to Remote Code Execution. The application deserializes the
App.txt settings file using Newtonsoft.Json with TypeNameHandling set to Objects. An attacker can provide a specially crafted JSON file containing a gadget chain, such as ObjectDataProvider, to execute arbitrary code when the application launches and saves its settings.Recommendations
Update to Beta 0.9.26020 or later.
Exploit
Fix
RCE
Deserialization of Untrusted Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Adb-Explorer
Newtonsoft.Json