PT-2026-108287 · Hazelcast · Hazelcast

CVE-2026-107726

·

Published

2026-10-08

·

Updated

2026-10-08

CVSS v4.0

9.3

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Hazelcast versions prior to 5.4.5 Hazelcast versions prior to 5.5.10 Hazelcast versions prior to 5.6.1 Hazelcast versions prior to 5.7.0
Description Improper validation of data supplied by a malicious client allows arbitrary reads from a cluster member's Java heap, off-heap data, and JVM process address space. This flaw can cause cluster members to crash and, in certain Enterprise Edition configurations, may lead to memory corruption and arbitrary code execution. Both slim and full distributions of the Community and Enterprise Editions are affected.
Recommendations Update to version 5.4.5. Update to version 5.5.10. Update to version 5.6.1. Update to version 5.7.0. Enable Hazelcast Security and enforce client authorization. Define an explicit allowlist for zero config Compact serialization. Avoid deploying clients on internet-facing non-secure networks or non-secure hosts. Protect the cluster using firewall rules. Disable unused features. Restrict cluster access to trusted clients only.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-107726
GHSA-6V25-8WQ6-XQ4J

Affected Products

Hazelcast