PT-2026-108287 · Hazelcast · Hazelcast
CVE-2026-107726
·
Published
2026-10-08
·
Updated
2026-10-08
CVSS v4.0
9.3
Critical
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Hazelcast versions prior to 5.4.5
Hazelcast versions prior to 5.5.10
Hazelcast versions prior to 5.6.1
Hazelcast versions prior to 5.7.0
Description
Improper validation of data supplied by a malicious client allows arbitrary reads from a cluster member's Java heap, off-heap data, and JVM process address space. This flaw can cause cluster members to crash and, in certain Enterprise Edition configurations, may lead to memory corruption and arbitrary code execution. Both slim and full distributions of the Community and Enterprise Editions are affected.
Recommendations
Update to version 5.4.5.
Update to version 5.5.10.
Update to version 5.6.1.
Update to version 5.7.0.
Enable Hazelcast Security and enforce client authorization.
Define an explicit allowlist for zero config Compact serialization.
Avoid deploying clients on internet-facing non-secure networks or non-secure hosts.
Protect the cluster using firewall rules.
Disable unused features.
Restrict cluster access to trusted clients only.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Hazelcast