Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 14 Aug 2026 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was detected in alldatacenter alldata up to 0.6.8. This affects the function Hessian2Input.readObject of the file /serialize/impl/HessianSerializer.java of the component xxl-rpc Listener. The manipulation results in deserialization. The attack may be performed from remote. The exploit is now public and may be used. The project closed the issue report as "not planned" without any further explanation. | |
| Title | alldatacenter alldata xxl-rpc Listener HessianSerializer.java Hessian2Input.readObject deserialization | |
| First Time appeared |
Alldata
Alldata alldata |
|
| Weaknesses | CWE-20 CWE-502 |
|
| CPEs | cpe:2.3:a:alldata:alldata:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Alldata
Alldata alldata |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-08-14T13:00:09.415Z
Reserved: 2026-08-14T05:50:11.826Z
Link: CVE-2026-19826
No data.
Status : Received
Published: 2026-08-14T13:17:38.333
Modified: 2026-08-14T13:17:38.333
Link: CVE-2026-19826
No data.
OpenCVE Enrichment
Updated: 2026-08-14T14:45:17Z