SB2026100112 - Multiple vulnerabilities in Hazelcast



SB2026100112 - Multiple vulnerabilities in Hazelcast

Published: October 1, 2026 Updated: October 1, 2026

Security Bulletin ID SB2026100112
CSH Severity
High
Patch available
YES
Number of vulnerabilities 10
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

High 20% Medium 30% Low 50%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 10 vulnerabilities.


1) Missing Authorization (CVE-ID: N/A)

CWE-ID: CWE-862 - Missing Authorization

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to execute arbitrary code on a Hazelcast member.

The vulnerability exists due to missing authorization checks in the IMap Predicates API when processing predicates submitted by a client. A remote user can submit a predicate through the API to execute arbitrary code on a Hazelcast member.


2) Input validation error (CVE-ID: N/A)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to read arbitrary memory and cause cluster member crashes or memory corruption potentially leading to remote code execution.

The vulnerability exists due to improper input validation in Hazelcast when handling client requests. A remote attacker can send requests to a cluster member to read arbitrary memory and cause cluster member crashes or memory corruption potentially leading to remote code execution.

Memory corruption is possible only in some Enterprise Edition configurations.


3) Missing Authorization (CVE-ID: N/A)

CWE-ID: CWE-862 - Missing Authorization

CVSSv4: 7.6 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to disclose information and execute arbitrary code.

The vulnerability exists due to missing authorization in the experimental declarative pipeline feature for Jet when processing Jet job submissions. A remote user can submit a Jet job without the required permission checks to disclose information and execute arbitrary code.

Jet must be enabled for exploitation.


4) Path traversal (CVE-ID: N/A)

CWE-ID: CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

CVSSv4: 7.6 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to write files to unauthorized locations on a member.

The vulnerability exists due to improper limitation of pathname validation in Jet when handling file-write input from a client. A remote user can submit a path traversal payload to write files to unauthorized locations on a member.

Remote code execution may be possible in some cases.


5) Input validation error (CVE-ID: N/A)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 6 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to read arbitrary files.

The vulnerability exists due to improper input validation in Jet functionality when handling Jet functionality requests. A remote user can abuse Jet functionality to read arbitrary files.

The issue is exploitable even when Jet is not enabled.


6) Missing Authorization (CVE-ID: N/A)

CWE-ID: CWE-862 - Missing Authorization

CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to disclose sensitive information and cause a denial of service.

The vulnerability exists due to missing authorization in the Predicate API when processing Predicate API filters. A remote user can bypass Predicate API filters to disclose sensitive information and cause a denial of service.


7) Deserialization of Untrusted Data (CVE-ID: N/A)

CWE-ID: CWE-502 - Deserialization of Untrusted Data

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to execute arbitrary code.

The vulnerability exists due to deserialization of untrusted data in IMap client deserialization when deserializing malicious data from an IMap. A remote user can place malicious data in an IMap to execute arbitrary code.

The H2 database library must be on the classpath of the client or member application.


8) Input validation error (CVE-ID: N/A)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to improper input validation in client and member error handling when connecting to a malicious member. A remote attacker can spoof a malicious member to execute arbitrary code.

In Kubernetes environments, exploitation may also expose service account tokens.


9) Deserialization of Untrusted Data (CVE-ID: N/A)

CWE-ID: CWE-502 - Deserialization of Untrusted Data

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to execute arbitrary code or disclose information.

The vulnerability exists due to insecure deserialization in JSON/BSON deserialization when processing JSON/BSON data from a client. A remote user can submit crafted JSON/BSON data to instantiate objects insecurely to execute arbitrary code or disclose information.


10) Input validation error (CVE-ID: N/A)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to execute arbitrary code.

The vulnerability exists due to improper input validation in the Hazelcast SQL class filter when evaluating user-supplied expressions. A remote user can submit expressions that instantiate unauthorized objects to execute arbitrary code.

Exploitation may be possible even if SQL is disabled.


Remediation

Install update from vendor's website.