๐Ÿ” CVE Alert

CVE-2026-19826

HIGH 7.3

alldatacenter alldata xxl-rpc Listener HessianSerializer.java Hessian2Input.readObject deserialization

CVSS Score
7.3
EPSS Score
0.0%
EPSS Percentile
0th

A vulnerability was detected in alldatacenter alldata up to 0.6.8. This affects the function Hessian2Input.readObject of the file /serialize/impl/HessianSerializer.java of the component xxl-rpc Listener. The manipulation results in deserialization. The attack may be performed from remote. The exploit is now public and may be used. The project closed the issue report as "not planned" without any further explanation.

CWE CWE-502 CWE-20
Vendor alldatacenter
Product alldata
Published Aug 14, 2026
Stay Ahead of the Next One

Get instant alerts for alldatacenter alldata

Be the first to know when new high vulnerabilities affecting alldatacenter alldata are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

alldatacenter / alldata
0.6.0 0.6.1 0.6.2 0.6.3 0.6.4 0.6.5 0.6.6 0.6.7 0.6.8

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
vuldb.com: https://vuldb.com/vuln/389959 vuldb.com: https://vuldb.com/vuln/389959/cti vuldb.com: https://vuldb.com/cve/CVE-2026-19826 vuldb.com: https://vuldb.com/submit/870236 github.com: https://github.com/alldatacenter/alldata/issues/832 github.com: https://github.com/alldatacenter/alldata/

Credits

๐Ÿ” fakebug (VulDB User) VulDB CNA Team