GHSA-w294-6q5q-53p8High

Hazelcast has an authorization bypass in IMap Predicates API

Published
October 8, 2026
Last Modified
October 8, 2026

🔗 CVE IDs covered (1)

📋 Description

Impact

Missing authorization checks in the Predicates API may allow a malicious client to execute arbitrary code on a Hazelcast member.

Patches

Enterprise customers should upgrade to a fixed version of Hazelcast Enterprise Edition:

  • 5.7.0
  • 5.6.1
  • 5.5.10
  • 5.4.5

Customers with extended support contracts should contact Hazelcast Support for information on patches for older versions.

Community Edition users should upgrade to version 5.7.0.

Workarounds

None - customers are advised to upgrade to a fixed version as soon as possible.

🎯 Affected products3

  • maven/com.hazelcast:hazelcast:= 5.6.0
  • maven/com.hazelcast:hazelcast:>= 5.5.0, < 5.5.10
  • maven/com.hazelcast:hazelcast:< 5.4.5

🔗 References (5)