{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/hazelcast-enterprise-edition--5.7.0--5.6.1--5.5.10--5.4.5/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"id":"CVE-2026-107726"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Hazelcast Enterprise Edition (\u003c 5.7.0, \u003c 5.6.1, \u003c 5.5.10, \u003c 5.4.5)","Hazelcast Community Edition (\u003c 5.7.0)"],"_cs_severities":["critical"],"_cs_tags":["vulnerability","remote-code-execution","hazelcast","java"],"_cs_type":"advisory","_cs_vendors":["Hazelcast"],"content_html":"\u003cp\u003eA critical security flaw (CVE-2026-107726) has been identified in both Hazelcast Enterprise and Community Editions, enabling low-privileged clients to access arbitrary memory on cluster members. This access encompasses Java heap memory, off-heap data, and the broader JVM process address space. The vulnerability is particularly severe because it allows for unauthorized data exfiltration and may be exploited to trigger cluster-wide denial-of-service (DoS) conditions. Furthermore, in specific Enterprise Edition configurations, the memory access primitive can be chained to achieve memory corruption, providing an attacker with a path to execute arbitrary code within the context of the Hazelcast process. Organizations running versions below 5.7.0, 5.6.1, 5.5.10, or 5.4.5 are at risk.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker establishes a connection to the Hazelcast cluster using a low-privileged client identity.\u003c/li\u003e\n\u003cli\u003eAttacker leverages the vulnerability in the Compact serialization or cluster member communication protocol to bypass existing authorization boundaries.\u003c/li\u003e\n\u003cli\u003eAttacker sends specifically crafted requests to the targeted cluster member.\u003c/li\u003e\n\u003cli\u003eThe Hazelcast member process parses the malicious input without proper boundary checks.\u003c/li\u003e\n\u003cli\u003eAttacker performs unauthorized reads against JVM heap memory or process address space to exfiltrate sensitive data.\u003c/li\u003e\n\u003cli\u003eAttacker sends malformed data that triggers memory corruption within the JVM process.\u003c/li\u003e\n\u003cli\u003eAttacker executes arbitrary code or crashes the cluster member.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows attackers to gain unauthorized access to sensitive data stored in-memory within Hazelcast clusters. Given the potential for remote code execution, attackers could gain full control over the compromised Hazelcast cluster nodes, leading to lateral movement, data theft, or service disruption. All sectors utilizing Hazelcast for high-performance in-memory computing are potentially affected.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for security and infrastructure teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003ePatch all instances to the fixed versions (Enterprise 5.7.0, 5.6.1, 5.5.10, 5.4.5; Community 5.7.0) immediately.\u003c/li\u003e\n\u003cli\u003eEnable and strictly enforce Hazelcast client authorization to prevent unauthorized access.\u003c/li\u003e\n\u003cli\u003eImplement an explicit allowlist for zero-config Compact serialization to restrict potential exploit vectors.\u003c/li\u003e\n\u003cli\u003eRestrict network access to cluster nodes via firewall rules to ensure only trusted, hardened clients can communicate with the cluster.\u003c/li\u003e\n\u003cli\u003eDisable all unused features to reduce the overall attack surface of the cluster members.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-09T07:58:32Z","date_published":"2026-10-09T07:58:32Z","id":"https://feed.craftedsignal.io/briefs/2026-10-hazelcast-memory-access/","summary":"A critical vulnerability in Hazelcast Enterprise and Community Editions allows unauthenticated or low-privileged clients to read arbitrary cluster member memory, potentially enabling remote code execution via memory corruption.","title":"Hazelcast Arbitrary Memory Access Vulnerability","url":"https://feed.craftedsignal.io/briefs/2026-10-hazelcast-memory-access/"}],"language":"en","title":"CraftedSignal Threat Feed - Hazelcast Enterprise Edition (\u003c 5.7.0, \u003c 5.6.1, \u003c 5.5.10, \u003c 5.4.5)","version":"https://jsonfeed.org/version/1.1"}