DEV Community

CVE Reports
CVE Reports

Posted on Originally published at cvereports.com

CVE-2026-107725: CVE-2026-107725: Remote Code Execution via Authorization Bypass in Hazelcast Predicates API

CVE-2026-107725: Remote Code Execution via Authorization Bypass in Hazelcast Predicates API

Vulnerability ID: CVE-2026-107725
CVSS Score: 8.7
Published: 2026-10-08

CVE-2026-107725 is a critical security bypass in Hazelcast where missing authorization checks in the MapPermission class permit unprivileged clients to issue queries containing aggregators or projections. This architectural oversight allows attackers to run arbitrary code on the cluster servers under the privileges of the active Hazelcast process.

TL;DR

An authorization bypass vulnerability in Hazelcast versions prior to 5.4.5, 5.5.10, and 5.6.1 allows authenticated users with minimal permissions to execute arbitrary Java code on cluster nodes by sending crafted aggregation or projection requests.


⚠️ Exploit Status: POC

Technical Details

  • CWE ID: CWE-862
  • Attack Vector: Network
  • CVSS Score: 8.7 (CVSS v4.0)
  • EPSS Score: 0.01 (Estimated)
  • Impact: Remote Code Execution (RCE)
  • Exploit Status: Proof-of-Concept Stage / Private
  • KEV Status: Not Listed

Affected Systems

  • Hazelcast Community Edition
  • Hazelcast Enterprise Edition
  • Hazelcast: < 5.4.5 (Fixed in: 5.4.5)
  • Hazelcast: >= 5.5.0, < 5.5.10 (Fixed in: 5.5.10)
  • Hazelcast: >= 5.6.0, < 5.6.1 (Fixed in: 5.6.1)

Code Analysis

Commit: 5d68f48

Add AGGREGATE and PROJECTION actions to MapPermission security configurations

@@ -25,12 +25,16 @@ public class MapPermission extends InstancePermission {
     private static final int LOCK = 64;
     private static final int INDEX = 128;
     private static final int INTERCEPT = 256;
-    private static final int ALL = CREATE | DESTROY | PUT | REMOVE | READ | LISTEN | LOCK | INDEX | INTERCEPT;
+    private static final int AGGREGATE = 1 << 9;
+    private static final int PROJECTION = 1 << 10;
+    private static final int ALL = CREATE | DESTROY | PUT | REMOVE | READ | LISTEN
+            | LOCK | INDEX | INTERCEPT | AGGREGATE | PROJECTION;

     public MapPermission(String name, String... actions) {
         super(name, actions);
     }

+    @SuppressWarnings("checkstyle:CyclomaticComplexity")
     @Override
     protected int initMask(String[] actions) {
         int mask = NONE;
@@ -57,6 +61,10 @@ protected int initMask(String[] actions) {
                 mask |= INDEX;
             } else if (ActionConstants.ACTION_INTERCEPT.equals(action)) {
                 mask |= INTERCEPT;
+            } else if (ActionConstants.ACTION_AGGREGATE.equals(action)) {
+                mask |= AGGREGATE;
+            } else if (ActionConstants.ACTION_PROJECTION.equals(action)) {
+                mask |= PROJECTION;
             }
         }
         return mask;
Enter fullscreen mode Exit fullscreen mode

Mitigation Strategies

  • Upgrade to patched Hazelcast versions (5.4.5, 5.5.10, 5.6.1, or 5.7.0)
  • Disable client-side User Code Deployment in cluster configuration
  • Enforce custom Java serialization filters (ObjectFilter) to block untrusted payloads
  • Restrict network access to the cluster ports to trusted systems only

Remediation Steps:

  1. Identify all running Hazelcast instances and check their version numbers.
  2. Apply upgrades to version 5.4.5, 5.5.10, 5.6.1, or 5.7.0 as appropriate.
  3. Review client security roles and ensure permission configurations do not grant excessive privileges.
  4. Modify hazelcast.xml to disable user-code-deployment if dynamic class loading is not required.

References


Read the full report for CVE-2026-107725 on our website for more details including interactive diagrams and full exploit analysis.

Top comments (0)