Input validation error in Hazelcast - #VU153045
Published: October 1, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to improper input validation in client and member error handling when connecting to a malicious member. A remote attacker can spoof a malicious member to execute arbitrary code.
In Kubernetes environments, exploitation may also expose service account tokens.