Skip to content
Threat Feed
high advisory updated

Authorization Bypass in Hazelcast IMap Predicates API

Hazelcast contains an authorization bypass vulnerability in the IMap Predicates API allowing unauthenticated remote code execution on cluster members via malicious predicate input.

CVE search metadata

CVE search record: CVE-2026-107725. KEV: no. Product: Hazelcast (< 5.4.5, 5.5.0-5.5.9, 5.6.0), Hazelcast (5.5.0-5.5.9). Brief: Authorization Bypass in Hazelcast IMap Predicates API. Brief link: https://feed.craftedsignal.io/briefs/2026-10-hazelcast-auth-bypass/

What's new

  • 1. new product Oct 9, 12:44 via bsi

Hazelcast has disclosed a critical authorization bypass vulnerability (CVE-2026-107725) affecting the IMap Predicates API. This vulnerability allows an unauthenticated or unauthorized remote attacker to supply malicious input to the predicate execution engine, which is subsequently processed without proper authorization checks. If successfully exploited, this flaw leads to remote code execution on the targeted Hazelcast member node. The vulnerability impacts Hazelcast Community and Enterprise editions, with specific affected version ranges including everything below 5.4.5, versions 5.5.0 through 5.5.9, and version 5.6.0. Organizations utilizing Hazelcast in exposed network environments are at risk of complete cluster node compromise. There are no available workarounds; remediation requires upgrading to the patched versions: 5.7.0, 5.6.1, 5.5.10, or 5.4.5.

Impact

Successful exploitation of CVE-2026-107725 results in arbitrary code execution on Hazelcast member nodes. This impact spans all organizations using vulnerable Hazelcast deployments, potentially leading to unauthorized data access, cluster-wide disruption, or lateral movement within the network where the Hazelcast member resides.

Recommendation

  • Upgrade all Hazelcast instances to the patched versions immediately: 5.7.0, 5.6.1, 5.5.10, or 5.4.5.
  • Review network access controls to ensure Hazelcast member ports (default 5701) are not exposed to untrusted or public networks.
  • Monitor logs for unusual serialized objects or unexpected Java class instantiations originating from client IP addresses.

Immediate actions

Upgrade Hazelcast instances to fixed versions (5.7.0, 5.6.1, 5.5.10, 5.4.5)

IT Operations 24h

Mitigations

Restrict network access to Hazelcast member ports

immediate Network Security

CVE-2026-107725