Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.4
CVE-2026-107725: Hazelcast lets low‑privilege user run code
CVE-2026-107725 · published 2 days ago
Summary
If you are using Hazelcast versions earlier than 5.4.5, 5.5.10, or 5.6.1, a user with only limited rights can cause the system to run their own programs on a Hazelcast server. This could let an attacker take control or disrupt your services. Upgrade to the latest patched versions (5.4.5 or newer, 5.5.10 or newer, 5.6.1 or newer, or 5.7.0) to fix the problem.
What to do
- Update hazelcast com.hazelcast:hazelcast to version 5.7.0.
- Update com.hazelcast:hazelcast to version 5.7.0.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| – | hazelcast | hazelcast | < 5.4.5 |
| maven | hazelcast | com.hazelcast:hazelcast |
5.6.0 >= 5.5.0, < 5.5.10 < 5.4.5 Fix: upgrade to 5.7.0
|
| Maven | hazelcast | com.hazelcast:hazelcast |
>= 5.6.0, < 5.7.0 >= 5.5.0, < 5.7.0 < 5.7.0 Fix: upgrade to 5.7.0
|
| maven | – | com.hazelcast:hazelcast |
5.6.0 >= 5.5.0, < 5.5.10 < 5.4.5 Fix: upgrade to 5.7.0
|
| Maven | – | com.hazelcast:hazelcast |
>= 5.6.0, < 5.7.0 >= 5.5.0, < 5.7.0 < 5.7.0 Fix: upgrade to 5.7.0
|
Original advisory text
Hazelcast: Authorization bypass in IMap Predicates API
Hazelcast is a unified real-time data platform combining stream processing with a fast data store. Prior to 5.4.5, 5.5.10, and 5.6.1, missing authorization checks in the IMap Predicates API allow a malicious client with limited privileges to execute arbitrary code on a Hazelcast cluster member. This issue is fixed in versions 5.4.5, 5.5.10, 5.6.1, and 5.7.0.
References
- https://docs.hazelcast.com/hazelcast/5.7/release-notes/enterprise URL
- https://github.com/hazelcast/hazelcast/security/advisories/GHSA-w294-6q5q-53p8 Vendor Advisory
- https://github.com/advisories/GHSA-w294-6q5q-53p8
- https://docs.hazelcast.com/hazelcast/5.7/release-notes/releases URL
- https://github.com/hazelcast/hazelcast Product
- https://github.com/hazelcast/hazelcast/commit/5d68f4828e2a914398a39f12fe11cafd33... Patch
- https://docs.hazelcast.com/hazelcast/5.7/release-notes/community URL
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/107xxx/CVE-2026-1077... Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-107725 Vendor Advisory
Internet-facing
14 days
Internal
At next upgrade
- Not known to be exploited
- Needs hands-on effort to exploit
- Gives an attacker full control
Severity
9.4
Critical
Type
CWE-862Missing Authorization
Timeline
Published8 Oct 2026
Updated10 Oct 2026
First seen8 Oct 2026
Sources
CVE-2026-107725 · NVD
CVE-2026-107725 · MITRE
GHSA-w294-6q5q-53p8 · GHSA
GHSA-w294-6q5q-53p8 · OSV
CVE-2026-107725 · OSV
Track software like this
Free during beta