Vulnerability Description
A vulnerability was detected in alldatacenter alldata up to 0.6.8. This affects the function Hessian2Input.readObject of the file /serialize/impl/HessianSerializer.java of the component xxl-rpc Listener. The manipulation results in deserialization. The attack may be performed from remote. The exploit is now public and may be used. The project closed the issue report as "not planned" without any further explanation.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://github.com/alldatacenter/alldata/
- https://github.com/alldatacenter/alldata/issues/832
- https://vuldb.com/cve/CVE-2026-19826
- https://vuldb.com/submit/870236
- https://vuldb.com/vuln/389959
- https://vuldb.com/vuln/389959/cti
- https://github.com/alldatacenter/alldata/issues/832
FAQ
What is CVE-2026-19826?
CVE-2026-19826 is a vulnerability with a CVSS score of 7.3 (HIGH). A vulnerability was detected in alldatacenter alldata up to 0.6.8. This affects the function Hessian2Input.readObject of the file /serialize/impl/HessianSerializer.java of the component xxl-rpc Listen...
How severe is CVE-2026-19826?
CVE-2026-19826 has been rated HIGH with a CVSS base score of 7.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-19826?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.