← Back
Web Application
CVE-2026-19826 high CVSS 7.3

A vulnerability was detected in alldatacenter alldata up to 0.6.8. This affects the function...

Summary

A vulnerability was detected in alldatacenter alldata up to 0.6.8. This affects the function...

AI summary openai / gpt-4o

alldatacenterのalldataバージョン0.6.8までに、xxl-rpc Listenerコンポーネント内のHessianSerializer.javaファイルのHessian2Input.readObject関数に脆弱性が発見されました。これはリモートからのデシリアライゼーション攻撃が可能で、悪用が既に公表されています。プロジェクトはこの問題の修正を「予定なし」としてクローズしました。
❓ What is the problem
デシリアライゼーション脆弱性
📍 Affected scope
alldatacenterのalldataバージョン0.6.8以下
🔥 Severity
リモートからの攻撃が可能で、既に悪用実証が公開されているため、高いリスクがある。
🔧 How to fix
現時点で修正プランはない。
🛡️ Workaround
特定の条件下でコンポーネントの使用を避ける。
🔍 Detection
該当バージョンの使用状況を確認し、Hessian2Input.readObjectの異常な動作を監視する。

References

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →