What is CVE-2026-19826?
CVE-2026-19826 is a remote deserialization vulnerability in alldatacenter alldata up to version 0.6.8, affecting the Hessian2Input.readObject function in xxl-rpc Listener's HessianSerializer.java. This could allow unauthenticated remote attackers to potentially execute code; immediate update to the latest version is recommended.
Azərbaycanca: CVE-2026-19826, alldatacenter alldata proqramının 0.6.8-ə qədər versiyalarında, xxl-rpc Listener komponentindəki HessianSerializer.java faylında Hessian2Input.readObject funksiyası vasitəsilə uzaqdan deserializasiya zəifliyidir. Bu, təsdiqlənməmiş uzaqdan hücumçulara potensial kod icrası imkanı yarada bilər; dərhal ən son versiyaya yeniləmə tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-502
FAQ2
Which component of alldatacenter alldata is affected by CVE-2026-19826?
This vulnerability affects the Hessian2Input.readObject function in the HessianSerializer.java file within the xxl-rpc Listener component.
What is the recommended action to mitigate CVE-2026-19826?
An immediate update to the latest version is recommended, as versions up to 0.6.8 are susceptible to unauthenticated remote code execution.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.