Input validation error in Hazelcast - #VU153047
Published: October 1, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary code.
The vulnerability exists due to improper input validation in the Hazelcast SQL class filter when evaluating user-supplied expressions. A remote user can submit expressions that instantiate unauthorized objects to execute arbitrary code.
Exploitation may be possible even if SQL is disabled.