CVE-2026-107725 PUBLISHED

Hazelcast: Authorization bypass in IMap Predicates API

Assigner: GitHub_M
Reserved: 08.10.2026 Published: 08.10.2026 Updated: 09.10.2026

Hazelcast is a unified real-time data platform combining stream processing with a fast data store. Prior to 5.4.5, 5.5.10, and 5.6.1, missing authorization checks in the IMap Predicates API allow a malicious client with limited privileges to execute arbitrary code on a Hazelcast cluster member. This issue is fixed in versions 5.4.5, 5.5.10, 5.6.1, and 5.7.0.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 8.7

Product Status

Vendor hazelcast
Product hazelcast
Versions
  • Version < 5.4.5 is affected
  • Version >= 5.5.0, < 5.5.10 is affected
  • Version >= 5.6.0, < 5.6.1 is affected

References

Problem Types

  • CWE-862: Missing Authorization CWE