Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.4

CVE-2026-107725: Hazelcast lets low‑privilege user run code

CVE-2026-107725 · published 2 days ago
Summary

If you are using Hazelcast versions earlier than 5.4.5, 5.5.10, or 5.6.1, a user with only limited rights can cause the system to run their own programs on a Hazelcast server. This could let an attacker take control or disrupt your services. Upgrade to the latest patched versions (5.4.5 or newer, 5.5.10 or newer, 5.6.1 or newer, or 5.7.0) to fix the problem.

What to do
  • Update hazelcast com.hazelcast:hazelcast to version 5.7.0.
  • Update com.hazelcast:hazelcast to version 5.7.0.
Affected software
Ecosystem VendorProductAffected versions
– hazelcast hazelcast < 5.4.5
maven hazelcast com.hazelcast:hazelcast 5.6.0
>= 5.5.0, < 5.5.10
< 5.4.5
Fix: upgrade to 5.7.0
Maven hazelcast com.hazelcast:hazelcast >= 5.6.0, < 5.7.0
>= 5.5.0, < 5.7.0
< 5.7.0
Fix: upgrade to 5.7.0
maven – com.hazelcast:hazelcast 5.6.0
>= 5.5.0, < 5.5.10
< 5.4.5
Fix: upgrade to 5.7.0
Maven – com.hazelcast:hazelcast >= 5.6.0, < 5.7.0
>= 5.5.0, < 5.7.0
< 5.7.0
Fix: upgrade to 5.7.0
Original advisory text
Hazelcast: Authorization bypass in IMap Predicates API
Hazelcast is a unified real-time data platform combining stream processing with a fast data store. Prior to 5.4.5, 5.5.10, and 5.6.1, missing authorization checks in the IMap Predicates API allow a malicious client with limited privileges to execute arbitrary code on a Hazelcast cluster member. This issue is fixed in versions 5.4.5, 5.5.10, 5.6.1, and 5.7.0.
Fix within
Internet-facing 14 days
Internal At next upgrade
  • Not known to be exploited
  • Needs hands-on effort to exploit
  • Gives an attacker full control
Severity
9.4 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-862Missing Authorization
Timeline
Published8 Oct 2026
Updated10 Oct 2026
First seen8 Oct 2026
Track software like this
Free during beta