CVE-2026-19826
alldatacenter alldata xxl-rpc Listener HessianSerializer.java Hessian2Input.readObject deserialization
CVSS Score
7.3
EPSS Score
0.0%
EPSS Percentile
0th
A vulnerability was detected in alldatacenter alldata up to 0.6.8. This affects the function Hessian2Input.readObject of the file /serialize/impl/HessianSerializer.java of the component xxl-rpc Listener. The manipulation results in deserialization. The attack may be performed from remote. The exploit is now public and may be used. The project closed the issue report as "not planned" without any further explanation.
| CWE | CWE-502 CWE-20 |
| Vendor | alldatacenter |
| Product | alldata |
| Published | Aug 14, 2026 |
Stay Ahead of the Next One
Get instant alerts for alldatacenter alldata
Be the first to know when new high vulnerabilities affecting alldatacenter alldata are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Affected Versions
alldatacenter / alldata
0.6.0 0.6.1 0.6.2 0.6.3 0.6.4 0.6.5 0.6.6 0.6.7 0.6.8
References
Credits
๐ fakebug (VulDB User) VulDB CNA Team