Junglewise Threat Intelligence

CVE-2026-12787: zhilink ADP Application Developer Platform deserialization in testConnection

CVE-2026-12787 · Severity: medium · CVSS 6.3 · Published 2026-06-21

Executive brief

A security vulnerability exists in the zhilink ADP Application Developer Platform, a tool used for building and managing software applications. An attacker can exploit this flaw to execute unauthorized commands or gain control over the system by sending a specially crafted database connection string. This could lead to data theft, service disruption, or unauthorized access to internal development resources.

Technical details

A deserialization vulnerability (CWE-502) exists in the 'testConnection' endpoint of zhilink ADP Application Developer Platform version 1.0.0. The issue stems from improper validation of the 'jdbcUrl' argument, which allows an attacker to provide a malicious JDBC URL that triggers the deserialization of untrusted data. This attack can be performed remotely by an authenticated user with low privileges (PR:L). Successful exploitation could lead to remote code execution (RCE) or unauthorized access to the underlying server. Public exploit code is reportedly available, and the vendor has not yet provided a patch or response.

Affected products

  • zhilink (智互联) ADP Application Developer Platform (应用开发者平台) 1.0.0

Timeline

  • 2026-06-21: disclosed: Vulnerability published via VulDB/NVD

References

Related threats