PT-2026-8026 · Unknown · Adb-Explorer+1

Blankshiro

·

Published

2026-02-13

·

Updated

2026-02-18

·

CVE-2026-26208

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ADB Explorer versions prior to Beta 0.9.26020
Description ADB Explorer, a fluent UI for ADB on Windows, contains a flaw due to Insecure Deserialization, potentially leading to Remote Code Execution. The application deserializes the App.txt settings file using Newtonsoft.Json with TypeNameHandling set to Objects. An attacker can provide a specially crafted JSON file containing a gadget chain, such as ObjectDataProvider, to execute arbitrary code when the application launches and saves its settings.
Recommendations Update to Beta 0.9.26020 or later.

Exploit

Fix

RCE

Deserialization of Untrusted Data

Weakness Enumeration

Related Identifiers

CVE-2026-26208
GHSA-49QX-WPXJ-P4MH

Affected Products

Adb-Explorer
Newtonsoft.Json