A vulnerability, which was classified as critical , was found in alldatacenter alldata up to 0.6.8 . This affects the function Hessian2Input.readObject of the file /serialize/impl/HessianSerializer.java of the component xxl-rpc Listener . The manipulation results in deserialization. This vulnerability was named CVE-2026-19826 . The attack may be performed from remote. In addition, an exploit is available. The project closed the issue report as "not planned" without any further explanation.