Missing Authorization in Hazelcast - #VU153040
Published: October 1, 2026
Vulnerability details
The vulnerability allows a remote user to disclose information and execute arbitrary code.
The vulnerability exists due to missing authorization in the experimental declarative pipeline feature for Jet when processing Jet job submissions. A remote user can submit a Jet job without the required permission checks to disclose information and execute arbitrary code.
Jet must be enabled for exploitation.