{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3ahazelcasthazelcast/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:hazelcast:hazelcast:*:*:*:*:*:*:*:*"],"_cs_cves":[{"id":"CVE-2026-107725"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Hazelcast (\u003c 5.4.5, 5.5.0-5.5.9, 5.6.0)","Hazelcast (5.5.0-5.5.9)"],"_cs_severities":["high"],"_cs_tags":["vulnerability","rce","java","hazelcast"],"_cs_type":"advisory","_cs_vendors":["Hazelcast"],"content_html":"\u003cp\u003eHazelcast has disclosed a critical authorization bypass vulnerability (CVE-2026-107725) affecting the IMap Predicates API. This vulnerability allows an unauthenticated or unauthorized remote attacker to supply malicious input to the predicate execution engine, which is subsequently processed without proper authorization checks. If successfully exploited, this flaw leads to remote code execution on the targeted Hazelcast member node. The vulnerability impacts Hazelcast Community and Enterprise editions, with specific affected version ranges including everything below 5.4.5, versions 5.5.0 through 5.5.9, and version 5.6.0. Organizations utilizing Hazelcast in exposed network environments are at risk of complete cluster node compromise. There are no available workarounds; remediation requires upgrading to the patched versions: 5.7.0, 5.6.1, 5.5.10, or 5.4.5.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-107725 results in arbitrary code execution on Hazelcast member nodes. This impact spans all organizations using vulnerable Hazelcast deployments, potentially leading to unauthorized data access, cluster-wide disruption, or lateral movement within the network where the Hazelcast member resides.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade all Hazelcast instances to the patched versions immediately: 5.7.0, 5.6.1, 5.5.10, or 5.4.5.\u003c/li\u003e\n\u003cli\u003eReview network access controls to ensure Hazelcast member ports (default 5701) are not exposed to untrusted or public networks.\u003c/li\u003e\n\u003cli\u003eMonitor logs for unusual serialized objects or unexpected Java class instantiations originating from client IP addresses.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-09T12:44:41Z","date_published":"2026-10-09T01:58:05Z","id":"https://feed.craftedsignal.io/briefs/2026-10-hazelcast-auth-bypass/","summary":"Hazelcast contains an authorization bypass vulnerability in the IMap Predicates API allowing unauthenticated remote code execution on cluster members via malicious predicate input.","title":"Authorization Bypass in Hazelcast IMap Predicates API","url":"https://feed.craftedsignal.io/briefs/2026-10-hazelcast-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:hazelcast:hazelcast:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}