Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.9
CVE-2026-107726: Hazelcast lets low‑privilege client read or crash memory
CVE-2026-107726 · published 2 days ago
Summary
In certain Hazelcast versions, a client that can connect to the cluster can request data it shouldn't see, potentially reading any memory content or causing the server to stop working. In some enterprise setups this could even allow the client to run its own code on the server. Updating to the latest Hazelcast release eliminates the problem.
What to do
- Update hazelcast com.hazelcast:hazelcast to version 5.7.0.
- Update com.hazelcast:hazelcast to version 5.7.0.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| – | hazelcast | hazelcast | < 5.4.5 |
| maven | hazelcast | com.hazelcast:hazelcast |
5.6.0 >= 5.5.0, < 5.5.10 < 5.4.5 Fix: upgrade to 5.7.0
|
| Maven | hazelcast | com.hazelcast:hazelcast |
>= 5.6.0, < 5.7.0 >= 5.5.0, < 5.7.0 < 5.7.0 Fix: upgrade to 5.7.0
|
| maven | – | com.hazelcast:hazelcast |
5.6.0 >= 5.5.0, < 5.5.10 < 5.4.5 Fix: upgrade to 5.7.0
|
| Maven | – | com.hazelcast:hazelcast |
>= 5.6.0, < 5.7.0 >= 5.5.0, < 5.7.0 < 5.7.0 Fix: upgrade to 5.7.0
|
Original advisory text
Hazelcast: Arbitrary member memory access by low-privileged client
Hazelcast is a unified real-time data platform combining stream processing with a fast data store. Prior to 5.4.5, 5.5.10, and 5.6.1, improper validation of data supplied by a malicious client able to connect to a cluster allows arbitrary reads from a cluster member's Java heap, off-heap data, and JVM process address space. The same flaw can crash cluster members and, in some Hazelcast Enterprise Edition configurations, corrupt memory with possible arbitrary code execution. Both slim and full distributions are affected. This issue is fixed in versions 5.4.5, 5.5.10, 5.6.1, and 5.7.0.
References
- https://github.com/hazelcast/hazelcast/security/advisories/GHSA-6v25-8wq6-xq4j Vendor Advisory
- https://github.com/hazelcast/hazelcast/releases/tag/v5.7.0 URL
- https://github.com/advisories/GHSA-6v25-8wq6-xq4j
- https://github.com/hazelcast/hazelcast Product
- https://docs.hazelcast.com/hazelcast/5.7/release-notes/community URL
- https://github.com/hazelcast/hazelcast/commit/361979da12f18950c24719db832ca6c5e7... Patch
- https://docs.hazelcast.com/hazelcast/5.7/release-notes/enterprise URL
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/107xxx/CVE-2026-1077... Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-107726 Vendor Advisory
Internet-facing
3 days
Internal
60 days
- Not known to be exploited
- Can be exploited automatically
- Gives an attacker full control
Severity
9.9
Critical
Type
CWE-20Improper Input Validation
Timeline
Published8 Oct 2026
Updated10 Oct 2026
First seen8 Oct 2026
Sources
CVE-2026-107726 · NVD
CVE-2026-107726 · MITRE
GHSA-6v25-8wq6-xq4j · GHSA
GHSA-6v25-8wq6-xq4j · OSV
CVE-2026-107726 · OSV
Track software like this
Free during beta