Skip to content
Saturday, October 10, 2026AboutContactRSS
Hazelcast releases patches for CVE-2026-107726 to block heap reads and code execution
Vulnerabilities

Hazelcast releases patches for CVE-2026-107726 to block heap reads and code execution

A CVSS 9.3 vulnerability in Hazelcast allows clients to read cluster memory and potentially execute code, with fixes available for multiple versions.

Key points

  • CVE-2026-107726 affects Hazelcast versions prior to 5.4.5, 5.5.10, and 5.6.1.
  • Attackers can read Java heap and off-heap data, crash members, or execute code in Enterprise setups.
  • Patches are available for Community Edition 5.7.0 and specific Enterprise Edition branches.

Hazelcast has released patches for a critical vulnerability that allows malicious clients to access sensitive memory data and potentially execute remote code. The flaw, tracked as CVE-2026-107726, affects both slim and full distributions of the data platform across multiple version lines.

What happened

According to the National Vulnerability Database and GitHub advisory GHSA-6v25-8wq6-xq4j, the issue stems from improper validation of data supplied by clients connecting to a Hazelcast cluster. A low-privileged malicious client can exploit this weakness to perform arbitrary reads from a cluster member’s Java heap, off-heap data, and JVM process address space.

This memory exposure can lead to cluster member crashes. In some configurations of Hazelcast Enterprise Edition, the flaw can also corrupt memory, which may result in arbitrary code execution. The vulnerability is rated 9.3 (Critical) on the CVSS scale and is associated with CWE-20 (Improper Input Validation). Both the Community Edition and Enterprise Edition are affected, covering versions prior to 5.4.5, versions 5.5.0 through 5.5.9, and version 5.6.0.

Why it matters

The ability to read arbitrary memory from cluster members exposes sensitive data stored in the Java heap and JVM process space. For organizations using Hazelcast for real-time data processing, this represents a significant breach of confidentiality and integrity. The potential for remote code execution in Enterprise configurations escalates the risk from data theft to full system compromise.

Hazelcast has confirmed that fixes are available. Community Edition users should upgrade to version 5.7.0. Enterprise Edition customers should upgrade to 5.4.5, 5.5.10, 5.6.1, or 5.7.0, depending on their current branch. Customers with extended support contracts for older versions were advised to contact Hazelcast Support for patch information.

What to watch

Organizations should monitor their Hazelcast clusters for unusual client connections or memory access patterns. Administrators should verify that all cluster nodes are running patched versions. Security teams should review logs for signs of cluster member crashes or unexpected memory corruption events, which may indicate exploitation attempts.

What to do and how to stay safe: Hazelcast

  • Audit your inventory to identify all instances of Hazelcast versions prior to 5.4.5, 5.5.10, and 5.6.1.
  • Apply the latest available patch immediately, prioritizing any clusters exposed to untrusted networks.
  • Ensure that Hazelcast Security is enabled and that client authorization is strictly enforced on all clusters.
  • Define an explicit allowlist for zero-config Compact serialization to limit deserialization risks.

General security guidance from the Patch Gazette newsroom. It is not confirmed advice from the organisations named in this story.

Frequently asked questions

Which Hazelcast versions are affected by CVE-2026-107726?

Versions prior to 5.4.5, versions 5.5.0 through 5.5.9, and version 5.6.0 are affected. Both slim and full distributions are vulnerable.

Is there a fix available for this vulnerability?

Yes, patches are available. Community Edition users should upgrade to 5.7.0. Enterprise Edition users should upgrade to 5.4.5, 5.5.10, 5.6.1, or 5.7.0.

What can attackers do with this flaw?

Attackers can read arbitrary memory data, crash cluster members, and potentially execute remote code in certain Enterprise Edition configurations.

Sources

  1. CVE Program
  2. GitHub Advisory Database
HazelcastCVE-2026-107726remote code executionmemory disclosureJava

Related stories