Arbitrary Data Read Vulnerability in Hazelcast Java Platform
CVE-2026-107726

9.3CRITICAL

Key Information:

Vendor

Hazelcast

Status
Vendor
CVE Published:
8 October 2026

What is CVE-2026-107726?

The vulnerability in Hazelcast allows a malicious client to connect to a data cluster, leading to improper validation of input data. This flaw opens the door for arbitrary reads from the Java heap memory, off-heap data, and the JVM's process address space. Such exploitation can not only crash cluster members but may also lead to memory corruption and potentially arbitrary code execution in some configurations of Hazelcast Enterprise Edition. Both slim and full distributions have been found at risk, but this issue has been proactively addressed in the later versions 5.4.5, 5.5.10, 5.6.1, and 5.7.0.

Affected Version(s)

hazelcast < 5.4.5 < 5.4.5

hazelcast >= 5.5.0, < 5.5.10 < 5.5.0, 5.5.10

hazelcast >= 5.6.0, < 5.6.1 < 5.6.0, 5.6.1

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.