← Blog · · df00tech

Hazelcast Patches Critical Memory-Disclosure and Crash Flaw Exploitable by Low-Privileged Clients

breaking ghsa maven CVE-2026-107726

What Happened

Hazelcast disclosed a vulnerability, tracked as CVE-2026-107726 (GHSA-6v25-8wq6-xq4j), affecting both Enterprise and Community Editions, across both the slim and full distributions. According to the advisory, a low-privileged, authenticated client connected to a Hazelcast cluster can read arbitrary data from a cluster member's memory, including Java heap, off-heap data, and other JVM process address space. The advisory also states such a client may be able to crash one or more cluster members, and in some Enterprise Edition configurations, corrupt memory contents — which Hazelcast says could potentially lead to remote code execution. A proof-of-concept is reported as publicly available.

Why It Matters

Hazelcast is widely used as an in-memory data grid and distributed caching layer, often holding session data, cached application state, or other sensitive in-memory objects. Because the flaw is exploitable by a client that already holds low-level cluster privileges — not an unauthenticated attacker — the real-world risk hinges on how broadly client access is granted and how exposed cluster members are to untrusted clients or networks. Any environment where Hazelcast security/authorization is not enforced, or where clients run on less-trusted hosts or networks, should treat this as high priority: unauthorized memory disclosure can leak secrets and data from any heap-resident object, and the crash/corruption potential threatens availability and, per the advisory, worse in some Enterprise setups.

What Defenders Should Watch For

  • Inventory all Hazelcast clusters and note version, edition, and distribution (slim/full) in use.
  • Confirm whether Hazelcast Security and client authorization are enabled — the advisory indicates unhardened clusters are the primary exposure path.
  • Check for an explicit allowlist on zero-config Compact serialization, as recommended in Hazelcast's hardening guide.
  • Review network exposure of cluster members and clients — flag any client nodes reachable from internet-facing or otherwise untrusted networks/hosts.
  • Hunt for anomalous client connections or unusual read patterns/volume against cluster members, and monitor for unexpected member crashes or restarts, which could indicate exploitation attempts.
  • Validate firewall rules restrict cluster member and client ports to trusted sources only.

What To Do Now

Hazelcast has published fixed versions: Enterprise Edition 5.7.0, 5.6.1, 5.5.10, and 5.4.5, and Community Edition 5.7.0. Organizations under extended support on older branches should contact Hazelcast Support directly. Where immediate upgrade isn't possible, Hazelcast's stated workaround is to restrict cluster access to trusted clients only and ensure those clients are themselves hardened against compromise.

Developing Intel

This is a same-day critical advisory and details may evolve as the community and Hazelcast provide further guidance. For the authoritative advisory, patch versions, and hardening links, see the GitHub Security Advisory GHSA-6v25-8wq6-xq4j.

Get new detections in your inbox

New ATT&CK coverage plus CISA KEV / CVE detection rules, roughly weekly. No spam, unsubscribe anytime.