Deserialization of Untrusted Data in Hazelcast - #VU153044

 

Deserialization of Untrusted Data in Hazelcast - #VU153044

Published: October 1, 2026


Vulnerability identifier: #VU153044
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-502
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute arbitrary code.

The vulnerability exists due to deserialization of untrusted data in IMap client deserialization when deserializing malicious data from an IMap. A remote user can place malicious data in an IMap to execute arbitrary code.

The H2 database library must be on the classpath of the client or member application.


Affected software

Hazelcast

Remediation

Install security update from vendor's website.

Hazelcast - addressed in versions 5.5.10, 5.6.2, 5.7.1

External References

Related Security Bulletins