Authorization Flaws in Hazelcast IMap Predicates API Allow Code Execution
CVE-2026-107725

8.7HIGH

Key Information:

Vendor

Hazelcast

Status
Vendor
CVE Published:
8 October 2026

What is CVE-2026-107725?

A serious vulnerability has been identified in the Hazelcast platform, specifically concerning the IMap Predicates API. Prior to versions 5.4.5, 5.5.10, and 5.6.1, the API lacked proper authorization checks, enabling a malicious actor with limited privileges to execute arbitrary code on a member of a Hazelcast cluster. The flaw presents a significant risk, as it could allow unauthorized access and manipulation of data within the cluster. This issue has been rectified in the latest releases, ensuring enhanced security and control within the Hazelcast environment.

Affected Version(s)

hazelcast < 5.4.5 < 5.4.5

hazelcast >= 5.5.0, < 5.5.10 < 5.5.0, 5.5.10

hazelcast >= 5.6.0, < 5.6.1 < 5.6.0, 5.6.1

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.