Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.9

CVE-2026-107726: Hazelcast lets low‑privilege client read or crash memory

CVE-2026-107726 · published 2 days ago
Summary

In certain Hazelcast versions, a client that can connect to the cluster can request data it shouldn't see, potentially reading any memory content or causing the server to stop working. In some enterprise setups this could even allow the client to run its own code on the server. Updating to the latest Hazelcast release eliminates the problem.

What to do
  • Update hazelcast com.hazelcast:hazelcast to version 5.7.0.
  • Update com.hazelcast:hazelcast to version 5.7.0.
Affected software
Ecosystem VendorProductAffected versions
– hazelcast hazelcast < 5.4.5
maven hazelcast com.hazelcast:hazelcast 5.6.0
>= 5.5.0, < 5.5.10
< 5.4.5
Fix: upgrade to 5.7.0
Maven hazelcast com.hazelcast:hazelcast >= 5.6.0, < 5.7.0
>= 5.5.0, < 5.7.0
< 5.7.0
Fix: upgrade to 5.7.0
maven – com.hazelcast:hazelcast 5.6.0
>= 5.5.0, < 5.5.10
< 5.4.5
Fix: upgrade to 5.7.0
Maven – com.hazelcast:hazelcast >= 5.6.0, < 5.7.0
>= 5.5.0, < 5.7.0
< 5.7.0
Fix: upgrade to 5.7.0
Original advisory text
Hazelcast: Arbitrary member memory access by low-privileged client
Hazelcast is a unified real-time data platform combining stream processing with a fast data store. Prior to 5.4.5, 5.5.10, and 5.6.1, improper validation of data supplied by a malicious client able to connect to a cluster allows arbitrary reads from a cluster member's Java heap, off-heap data, and JVM process address space. The same flaw can crash cluster members and, in some Hazelcast Enterprise Edition configurations, corrupt memory with possible arbitrary code execution. Both slim and full distributions are affected. This issue is fixed in versions 5.4.5, 5.5.10, 5.6.1, and 5.7.0.
Fix within
Internet-facing 3 days
Internal 60 days
  • Not known to be exploited
  • Can be exploited automatically
  • Gives an attacker full control
Severity
9.9 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-20Improper Input Validation
Timeline
Published8 Oct 2026
Updated10 Oct 2026
First seen8 Oct 2026
Track software like this
Free during beta