Arbitrary Data Read Vulnerability in Hazelcast Java Platform
CVE-2026-107726
9.3CRITICAL
What is CVE-2026-107726?
The vulnerability in Hazelcast allows a malicious client to connect to a data cluster, leading to improper validation of input data. This flaw opens the door for arbitrary reads from the Java heap memory, off-heap data, and the JVM's process address space. Such exploitation can not only crash cluster members but may also lead to memory corruption and potentially arbitrary code execution in some configurations of Hazelcast Enterprise Edition. Both slim and full distributions have been found at risk, but this issue has been proactively addressed in the later versions 5.4.5, 5.5.10, 5.6.1, and 5.7.0.
Affected Version(s)
hazelcast < 5.4.5 < 5.4.5
hazelcast >= 5.5.0, < 5.5.10 < 5.5.0, 5.5.10
hazelcast >= 5.6.0, < 5.6.1 < 5.6.0, 5.6.1
