CVE-2026-107726: Unrestricted Deserialization in Hazelcast Zero Config Compact Serialization
Vulnerability ID: CVE-2026-107726
CVSS Score: 9.3
Published: 2026-10-08
Improper validation of dynamic class resolution within Hazelcast's Zero Config Compact Serialization allows unauthenticated clients to trigger reflective class instantiation. This flaw can be exploited to read arbitrary JVM heap or off-heap memory, crash cluster nodes, or achieve arbitrary code execution under specific classpath conditions. This issue is resolved in Hazelcast versions 5.4.5, 5.5.10, 5.6.1, and 5.7.0.
TL;DR
Hazelcast Zero Config Compact Serialization permits arbitrary reflective class instantiation, causing sensitive memory leaks, Denial of Service, or remote code execution.
Technical Details
- CWE ID: CWE-20
- Attack Vector: Network
- CVSS v4.0: 9.3 (Critical)
- EPSS Score: Not Available
- Exploit Status: none
- KEV Status: Not Listed
Affected Systems
- Hazelcast Community Edition
- Hazelcast Enterprise Edition
-
Hazelcast Community Edition: < 5.4.5 (Fixed in:
5.4.5) -
Hazelcast Community Edition: >= 5.5.0, < 5.5.10 (Fixed in:
5.5.10) -
Hazelcast Community Edition: == 5.6.0 (Fixed in:
5.6.1)
Code Analysis
Commit: 361979d
Reflective compact serialization filtering CTT-687
Exploit Details
- Vendor Advisory: Official security advisory for CVE-2026-107726 detailing the dynamic serialization flaw and remediation
Mitigation Strategies
- Upgrade Hazelcast to the latest secure versions (5.4.5, 5.5.10, 5.6.1, or 5.7.0+)
- Configure custom blocklists and allowlists using the zero-config-filter element
- Deploy network microsegmentation to restrict access to Hazelcast ports (default 5701)
Remediation Steps:
- Identify all Hazelcast deployments in the environment and determine their current version.
- Download and apply updates for Hazelcast Community or Enterprise Edition according to the release guidance.
- If upgrading is delayed, edit hazelcast.xml or hazelcast.yaml to define a zero-config-filter restrictively.
- Restart the cluster members sequentially to apply the new configurations and ensure secure serialization policies are active.
References
Read the full report for CVE-2026-107726 on our website for more details including interactive diagrams and full exploit analysis.
Top comments (0)