Path traversal in Hazelcast - #VU153041
Published: October 1, 2026
Vulnerability details
The vulnerability allows a remote user to write files to unauthorized locations on a member.
The vulnerability exists due to improper limitation of pathname validation in Jet when handling file-write input from a client. A remote user can submit a path traversal payload to write files to unauthorized locations on a member.
Remote code execution may be possible in some cases.