Hazelcast is a unified real-time data platform combining stream processing with a fast data store. Prior to 5.4.5, 5.5.10, and 5.6.1, missing authorization checks in the IMap Predicates API allow a malicious client with limited privileges to execute arbitrary code on a Hazelcast cluster member. This issue is fixed in versions 5.4.5, 5.5.10, 5.6.1, and 5.7.0.

Project Subscriptions

Vendors Products
Hazelcast Subscribe
Hazelcast Subscribe
Advisories
Source ID Title
Github GHSA Github GHSA GHSA-w294-6q5q-53p8 Hazelcast has an authorization bypass in IMap Predicates API
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Fri, 09 Oct 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 09 Oct 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-749
References
Metrics threat_severity

None

cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

threat_severity

Important


Fri, 09 Oct 2026 00:30:00 +0000

Type Values Removed Values Added
First Time appeared Hazelcast
Hazelcast hazelcast
Vendors & Products Hazelcast
Hazelcast hazelcast

Thu, 08 Oct 2026 22:15:00 +0000

Type Values Removed Values Added
Description Hazelcast is a unified real-time data platform combining stream processing with a fast data store. Prior to 5.4.5, 5.5.10, and 5.6.1, missing authorization checks in the IMap Predicates API allow a malicious client with limited privileges to execute arbitrary code on a Hazelcast cluster member. This issue is fixed in versions 5.4.5, 5.5.10, 5.6.1, and 5.7.0.
Title Hazelcast: Authorization bypass in IMap Predicates API
Weaknesses CWE-862
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-09T14:53:26.897Z

Reserved: 2026-10-08T17:21:52.976Z

Link: CVE-2026-107725

cve-icon Vulnrichment

Updated: 2026-10-09T14:52:18.386Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-08T22:17:28.967

Modified: 2026-10-09T16:35:35.900

Link: CVE-2026-107725

cve-icon Redhat

Severity : Important

Publid Date: 2026-10-08T22:04:28Z

Links: CVE-2026-107725 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-10-09T14:15:09Z

Weaknesses