Missing Authorization in Hazelcast - #VU153040

 

Missing Authorization in Hazelcast - #VU153040

Published: October 1, 2026


Vulnerability identifier: #VU153040
CSH Severity: Low
CVSS v4: 7.6 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-862
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose information and execute arbitrary code.

The vulnerability exists due to missing authorization in the experimental declarative pipeline feature for Jet when processing Jet job submissions. A remote user can submit a Jet job without the required permission checks to disclose information and execute arbitrary code.

Jet must be enabled for exploitation.


Affected software

Hazelcast

Remediation

Install security update from vendor's website.

Hazelcast - addressed in versions 5.5.10, 5.6.2, 5.7.1

External References

Related Security Bulletins