<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Hazelcast Enterprise Edition (&lt; 5.7.0, &lt; 5.6.1, &lt; 5.5.10, &lt; 5.4.5) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/hazelcast-enterprise-edition--5.7.0--5.6.1--5.5.10--5.4.5/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Fri, 09 Oct 2026 07:58:32 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/hazelcast-enterprise-edition--5.7.0--5.6.1--5.5.10--5.4.5/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Hazelcast Arbitrary Memory Access Vulnerability</title><link>https://feed.craftedsignal.io/briefs/2026-10-hazelcast-memory-access/</link><pubDate>Fri, 09 Oct 2026 07:58:32 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-hazelcast-memory-access/</guid><description>A critical vulnerability in Hazelcast Enterprise and Community Editions allows unauthenticated or low-privileged clients to read arbitrary cluster member memory, potentially enabling remote code execution via memory corruption.</description><content:encoded><![CDATA[<p>A critical security flaw (CVE-2026-107726) has been identified in both Hazelcast Enterprise and Community Editions, enabling low-privileged clients to access arbitrary memory on cluster members. This access encompasses Java heap memory, off-heap data, and the broader JVM process address space. The vulnerability is particularly severe because it allows for unauthorized data exfiltration and may be exploited to trigger cluster-wide denial-of-service (DoS) conditions. Furthermore, in specific Enterprise Edition configurations, the memory access primitive can be chained to achieve memory corruption, providing an attacker with a path to execute arbitrary code within the context of the Hazelcast process. Organizations running versions below 5.7.0, 5.6.1, 5.5.10, or 5.4.5 are at risk.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>Attacker establishes a connection to the Hazelcast cluster using a low-privileged client identity.</li>
<li>Attacker leverages the vulnerability in the Compact serialization or cluster member communication protocol to bypass existing authorization boundaries.</li>
<li>Attacker sends specifically crafted requests to the targeted cluster member.</li>
<li>The Hazelcast member process parses the malicious input without proper boundary checks.</li>
<li>Attacker performs unauthorized reads against JVM heap memory or process address space to exfiltrate sensitive data.</li>
<li>Attacker sends malformed data that triggers memory corruption within the JVM process.</li>
<li>Attacker executes arbitrary code or crashes the cluster member.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows attackers to gain unauthorized access to sensitive data stored in-memory within Hazelcast clusters. Given the potential for remote code execution, attackers could gain full control over the compromised Hazelcast cluster nodes, leading to lateral movement, data theft, or service disruption. All sectors utilizing Hazelcast for high-performance in-memory computing are potentially affected.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritized actions for security and infrastructure teams:</p>
<ul>
<li>Patch all instances to the fixed versions (Enterprise 5.7.0, 5.6.1, 5.5.10, 5.4.5; Community 5.7.0) immediately.</li>
<li>Enable and strictly enforce Hazelcast client authorization to prevent unauthorized access.</li>
<li>Implement an explicit allowlist for zero-config Compact serialization to restrict potential exploit vectors.</li>
<li>Restrict network access to cluster nodes via firewall rules to ensure only trusted, hardened clients can communicate with the cluster.</li>
<li>Disable all unused features to reduce the overall attack surface of the cluster members.</li>
</ul>
]]></content:encoded><category domain="severity">critical</category><category domain="type">advisory</category><category>vulnerability</category><category>remote-code-execution</category><category>hazelcast</category><category>java</category></item></channel></rss>