CVE
CVE-2026-19826
0field notes · 1digest CVSS 7.3
The verdict
AllData (alldatacenter/alldata) up to version 0.6.8 has a remote deserialization bug in its Hessian2 serializer, reachable through the xxl-rpc listener. An attacker can send a malicious serialized object over the network to get code execution. A public exploit exists, and the project maintainers closed the report as 'not planned,' meaning no fix is coming. CVSS 7.3.
Patch urgency · Patch within 24 hours
Daily digests