Hazelcast is a unified real-time data platform combining stream processing with a fast data store. Prior to 5.4.5, 5.5.10, and 5.6.1, missing authorization checks in the IMap Predicates API allow a malicious client with limited privileges to execute arbitrary code on a Hazelcast cluster member. This issue is fixed in versions 5.4.5, 5.5.10, 5.6.1, and 5.7.0.

Project Subscriptions

No data.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-w294-6q5q-53p8 Hazelcast has an authorization bypass in IMap Predicates API
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 08 Oct 2026 22:15:00 +0000

Type Values Removed Values Added
Description Hazelcast is a unified real-time data platform combining stream processing with a fast data store. Prior to 5.4.5, 5.5.10, and 5.6.1, missing authorization checks in the IMap Predicates API allow a malicious client with limited privileges to execute arbitrary code on a Hazelcast cluster member. This issue is fixed in versions 5.4.5, 5.5.10, 5.6.1, and 5.7.0.
Title Hazelcast: Authorization bypass in IMap Predicates API
Weaknesses CWE-862
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-08T22:04:28.446Z

Reserved: 2026-10-08T17:21:52.976Z

Link: CVE-2026-107725

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-08T22:17:28.967

Modified: 2026-10-08T22:17:28.967

Link: CVE-2026-107725

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses