PT-2026-51205 · Zhilink · Adp Application Developer Platform

·

CVE-2026-12787

·

Published

2026-06-21

·

Updated

2026-06-21

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions zhilink ADP Application Developer Platform version 1.0.0
Description A remote deserialization issue exists in the 'testConnection' endpoint. Manipulation of the jdbcUrl argument allows for this attack. Deserialization is a process where data is converted back into an object, which can be exploited to execute unauthorized code if the input is not properly validated.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-12787

Affected Products

Adp Application Developer Platform