PatchDayAlert

CVE

CVE-2026-19826

0field notes · 1digest CVSS 7.3

The verdict

AllData (alldatacenter/alldata) up to version 0.6.8 has a remote deserialization bug in its Hessian2 serializer, reachable through the xxl-rpc listener. An attacker can send a malicious serialized object over the network to get code execution. A public exploit exists, and the project maintainers closed the report as 'not planned,' meaning no fix is coming. CVSS 7.3.

Patch urgency · Patch within 24 hours


Daily digests