CVE-2026-107726 — Hazelcast is a unified real-time data platform combining stream processing with a fast data store.
Description
Hazelcast is a unified real-time data platform combining stream processing with a fast data store. Prior to 5.4.5, 5.5.10, and 5.6.1, improper validation of data supplied by a malicious client able to connect to a cluster allows arbitrary reads from a cluster member's Java heap, off-heap data, and JVM process address space. The same flaw can crash cluster members and, in some Hazelcast Enterprise Edition configurations, corrupt memory with possible arbitrary code execution. Both slim and full distributions are affected. This issue is fixed in versions 5.4.5, 5.5.10, 5.6.1, and 5.7.0.
CVSS v4.0 base metrics
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XCritical severity
Band computed from the CVSS base score, not the source's own label — so it means the same thing across every feed.
AV
Network
Attack Vector
AC
Low
Attack Complexity
AT
None
Attack Requirements
PR
None
Privileges Required
UI
None
User Interaction
VC
High
Confidentiality (Vulnerable System)
VI
High
Integrity (Vulnerable System)
VA
High
Availability (Vulnerable System)
SC
None
Confidentiality (Subsequent System)
SI
None
Integrity (Subsequent System)
SA
None
Availability (Subsequent System)
References
- advisory[email protected]https://docs.hazelcast.com/hazelcast/5.7/release-notes/community
- advisory[email protected]https://docs.hazelcast.com/hazelcast/5.7/release-notes/enterprise
- advisory[email protected]https://github.com/hazelcast/hazelcast/commit/361979da12f18950c24719db832ca6c5e7c0534f
- advisory[email protected]https://github.com/hazelcast/hazelcast/releases/tag/v5.7.0
- advisory[email protected]https://github.com/hazelcast/hazelcast/security/advisories/GHSA-6v25-8wq6-xq4j
Related threats
same CWE or vendorCVE-2026-107720 — fast-jwt provides fast JSON Web Token (JWT) implementation.
CVE-2026-107720 · 1h ago
CVE-2026-107717 — Banks generates meaningful LLM prompts using a simple template language.
CVE-2026-107717 · 1h ago
Coraza: URL-encoded form Content-Type parameters bypass Coraza body inspection
OSV · 6h ago
Coraza: Multipart filename* (RFC 5987) charset restriction lets a decoy filename bypass FILES-based rules
OSV · 6h ago
Coraza: ProcessURI silently drops QUERY_STRING and ARGS_GET on URI parse failure — defense-in-depth bypass for non-net/http integrations
OSV · 6h ago
Coraza body processor has a JSON key collision that allows unauthenticated attackers to bypass OWASP CRS inspection
OSV · 6h ago