CVE 7.8 HIGH

ADB Explorer Vulnerable to Remote Code Execution via Insecure Deserialization_CVE-2026-26208

7.8 / 10
HIGH
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Description

ADB Explorer is a fluent UI for ADB on Windows. Prior to Beta 0.9.26020, ADB Explorer is vulnerable to Insecure Deserialization leading to Remote Code Execution. The application attempts to deserialize the App.txt settings file using Newtonsoft.Json with TypeNameHandling set to Objects. This allows an attacker to supply a crafted JSON file containing a gadget chain (e.g., ObjectDataProvider) to execute arbitrary code when the application launches and subsequently saves its settings. This vulnerability is fixed in Beta 0.9.26020.

Basic Information

ID CVE-2026-26208
Source GitHub_M
Published Feb 13, 2026 at 18:48
Modified Feb 13, 2026 at 19:21

Affected Product

Vendor Alex4SSB
Product ADB-Explorer
Version < Beta 0.9.26020
Affected Versions Alex4SSB ADB-Explorer < Beta 0.9.26020

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.