CVE-2026-107726
Received Received - Intake

Memory Corruption in Hazelcast Data Platform

Vulnerability report for CVE-2026-107726, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: GitHub, Inc.

Description

Hazelcast is a unified real-time data platform combining stream processing with a fast data store. Prior to 5.4.5, 5.5.10, and 5.6.1, improper validation of data supplied by a malicious client able to connect to a cluster allows arbitrary reads from a cluster member's Java heap, off-heap data, and JVM process address space. The same flaw can crash cluster members and, in some Hazelcast Enterprise Edition configurations, corrupt memory with possible arbitrary code execution. Both slim and full distributions are affected. This issue is fixed in versions 5.4.5, 5.5.10, 5.6.1, and 5.7.0.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-09
AI Q&A
2026-10-09
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
hazelcast hazelcast < 5.4.5
hazelcast hazelcast >= 5.5.0, < 5.5.10
hazelcast hazelcast >= 5.6.0, < 5.6.1

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-20 The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in Hazelcast versions before 5.4.5, 5.5.10, and 5.6.1 allows a malicious client to bypass data validation and read arbitrary data from a cluster member's Java heap, off-heap storage, or JVM process memory. It can also crash cluster members and, in some Enterprise Edition setups, corrupt memory potentially leading to arbitrary code execution.

Impact Analysis

An attacker could exploit this to steal sensitive data stored in memory, disrupt cluster operations by crashing nodes, or execute malicious code in Enterprise Edition environments. This could lead to data breaches, service outages, or complete system compromise depending on the Hazelcast deployment.

Compliance Impact

This vulnerability could violate GDPR by exposing personal data in memory or HIPAA by leaking protected health information. Organizations using vulnerable Hazelcast versions may face compliance violations, legal penalties, and reputational damage due to unauthorized data access or disclosure.

Mitigation Strategies

Upgrade Hazelcast to a fixed version (5.4.5, 5.5.10, 5.6.1, or 5.7.0) immediately to address the improper data validation flaw.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-107726. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart