CVE-2026-107725: Hazelcast: Authorization bypass in IMap Predicates API
Impact
Missing authorization checks in the Predicates API may allow a malicious client to execute arbitrary code on a Hazelcast member.
Patches
Enterprise customers should upgrade to a fixed version of Hazelcast Enterprise Edition: 5.7.0 5.6.1 5.5.10 5.4.5 Customers with extended support contracts should contact Hazelcast Support for information on patches for older versions.
Community Edition users should upgrade to version 5.7.0.
Workarounds None - customers are advised to upgrade to a fixed version as soon as possible.
Other sources
Hazelcast is a unified real-time data platform combining stream processing with a fast data store. Prior to 5.4.5, 5.5.10, and 5.6.1, missing authorization checks in the IMap Predicates API allow a malicious client with limited privileges to execute arbitrary code on a Hazelcast cluster member. This issue is fixed in versions 5.4.5, 5.5.10, 5.6.1, and 5.7.0.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
maven/com.hazelcast:hazelcastto a version that resolves this vulnerability.Fixed in 5.7.0 - Upgrade
Upgrade
Hazelcastto a version that resolves this vulnerability.Fixed in 5.7.0
Event History
Frequently Asked Questions
Which deployments are exposed?
Hazelcast deployments running versions earlier than 5.4.5, 5.5.10, or 5.6.1 are affected. The issue is also fixed in 5.7.0.
What level of access does an attacker need?
An attacker needs to act as a malicious Hazelcast client with limited privileges. The missing authorization checks in the IMap Predicates API can then allow execution of arbitrary code on a Hazelcast cluster member.
What is the remediation?
Upgrade Hazelcast to a fixed release: 5.4.5, 5.5.10, 5.6.1, or 5.7.0.