CVE-2026-107726
Last modified
CVE-2026-107726 is a critical-severity vulnerability rated 9.3/10 on the CVSS scale. Hazelcast is a unified real-time data platform combining stream processing with a fast data store. Prior to 5.4.5, 5.5.10, and 5.6.1, improper validation of data supplied by a malicious client able to connect to a cluster allows arbitrary reads from a cluster member's Java heap, off-heap data, and JVM process address space. EPSS estimates a 0.38% chance of exploitation in the next 30 days.
Description
Hazelcast is a unified real-time data platform combining stream processing with a fast data store. Prior to 5.4.5, 5.5.10, and 5.6.1, improper validation of data supplied by a malicious client able to connect to a cluster allows arbitrary reads from a cluster member's Java heap, off-heap data, and JVM process address space. The same flaw can crash cluster members and, in some Hazelcast Enterprise Edition configurations, corrupt memory with possible arbitrary code execution. Both slim and full distributions are affected. This issue is fixed in versions 5.4.5, 5.5.10, 5.6.1, and 5.7.0.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| hazelcast | hazelcast | < 5.4.5; >= 5.5.0, < 5.5.10; >= 5.6.0, < 5.6.1 |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2026-107726?
How severe is CVE-2026-107726?
How do I fix CVE-2026-107726?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-107720fast-jwt provides fast JSON Web Token (JWT) implementation. …7.4
- CVE-2026-107721fast-jwt provides fast JSON Web Token (JWT) implementation. …5.9
- CVE-2026-107722fast-jwt provides fast JSON Web Token (JWT) implementation. …9.8
- CVE-2026-107723fast-jwt provides fast JSON Web Token (JWT) implementation. …8.1
- CVE-2026-107724fast-jwt provides fast JSON Web Token (JWT) implementation. …7.4
- CVE-2026-107725Hazelcast is a unified real-time data platform combining str…8.7
- CVE-2026-107727Strawberry GraphQL is a library for creating GraphQL APIs. F…3.7
- CVE-2026-107728Strawberry GraphQL is a library for creating GraphQL APIs. F…7.5
- CVE-2026-107729SumatraPDF is a multi-format reader for Windows. In 3.7.0.22…5.5
- CVE-2026-10773The DHCPv4 client helper net_dhcpv4_msg_type_name() in subsy…5.4
- CVE-2026-107730SumatraPDF is a multi-format reader for Windows. In 3.7.0.22…5.5
- CVE-2026-107731SumatraPDF is a multi-format reader for Windows. In 3.7.0.22…5.5
Are you affected by CVE-2026-107726?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
