Input validation error in Hazelcast - #VU153047

 

Input validation error in Hazelcast - #VU153047

Published: October 1, 2026


Vulnerability identifier: #VU153047
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute arbitrary code.

The vulnerability exists due to improper input validation in the Hazelcast SQL class filter when evaluating user-supplied expressions. A remote user can submit expressions that instantiate unauthorized objects to execute arbitrary code.

Exploitation may be possible even if SQL is disabled.


Affected software

Hazelcast

Remediation

Install security update from vendor's website.

Hazelcast - addressed in versions 5.4.5, 5.5.10, 5.6.2, 5.7.0

External References

Related Security Bulletins