CVE-2026-19826 | alldatacenter alldata up to 0.6.8 xxl-rpc Listener HessianSerializer.java Hessian2Input.readObject deserialization (Issue 832)

SecurityVulns

A vulnerability, which was classified as critical, was found in alldatacenter alldata up to 0.6.8. This affects the function Hessian2Input.readObject of the file /serialize/impl/HessianSerializer.java of the component xxl-rpc Listener. The manipulation results in deserialization.

This vulnerability was named CVE-2026-19826. The attack may be performed from remote. In addition, an exploit is available.

The project closed the issue report as “not planned” without any further explanation.VulDB Recent EntriesRead More