{"id":"CVE-2026-107725","summary":"Hazelcast: Authorization bypass in IMap Predicates API","details":"Hazelcast is a unified real-time data platform combining stream processing with a fast data store. Prior to 5.4.5, 5.5.10, and 5.6.1, missing authorization checks in the IMap Predicates API allow a malicious client with limited privileges to execute arbitrary code on a Hazelcast cluster member. This issue is fixed in versions 5.4.5, 5.5.10, 5.6.1, and 5.7.0.","aliases":["GHSA-w294-6q5q-53p8"],"modified":"2026-10-10T07:06:00.886917440Z","published":"2026-10-08T22:04:28.446Z","database_specific":{"unresolved_ranges":[{"extracted_events":[{"fixed":"5.4.5"},{"introduced":"5.5.0"},{"fixed":"5.5.10"},{"introduced":"5.6.0"},{"fixed":"5.6.1"}],"source":"AFFECTED_FIELD"}],"cna_assigner":"GitHub_M","cwe_ids":["CWE-862"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/107xxx/CVE-2026-107725.json"},"references":[{"type":"WEB","url":"https://docs.hazelcast.com/hazelcast/5.7/release-notes/community"},{"type":"WEB","url":"https://docs.hazelcast.com/hazelcast/5.7/release-notes/enterprise"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/107xxx/CVE-2026-107725.json"},{"type":"ADVISORY","url":"https://github.com/hazelcast/hazelcast/security/advisories/GHSA-w294-6q5q-53p8"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107725"},{"type":"FIX","url":"https://github.com/hazelcast/hazelcast/commit/5d68f4828e2a914398a39f12fe11cafd335cefe0"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/hazelcast/hazelcast","events":[{"introduced":"0"},{"fixed":"5d68f4828e2a914398a39f12fe11cafd335cefe0"}],"database_specific":{"source":"REFERENCES"}}],"versions":["v3.5.1-stale","v3.3-EA2","v3.3-EA","v3.2","v3.1","v3.0","v3.0-RC1","v2.1","v2.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-107725.json","vanir_signatures":[{"signature_type":"Line","signature_version":"v1","source":"https://github.com/hazelcast/hazelcast/commit/5d68f4828e2a914398a39f12fe11cafd335cefe0","target":{"file":"hazelcast/src/main/java/com/hazelcast/security/permission/MapPermission.java"},"deprecated":false,"digest":{"line_hashes":["321533459365205565978499440684630695056","272138371892918640857095276531298074149","88689270638530874062282348820298147878","10350182487460076834028470316505814003","76226291742575354878223226978687504795","256677390958049350257027372711493297684","20876677224954927201659462078225942016","300961971269372967818475183289606166844","314113651467673165631972115752452297727","175188447386048221027370919475769468373","201132654331158968980910831655894954474"],"threshold":0.9},"id":"CVE-2026-107725-7ac7b441"},{"deprecated":false,"digest":{"function_hash":"316420227618059482255278640897459283083","length":935},"id":"CVE-2026-107725-ecd1ef6e","signature_type":"Function","signature_version":"v1","source":"https://github.com/hazelcast/hazelcast/commit/5d68f4828e2a914398a39f12fe11cafd335cefe0","target":{"file":"hazelcast/src/main/java/com/hazelcast/security/permission/MapPermission.java","function":"initMask"}}],"vanir_signatures_modified":"2026-10-10T07:06:00Z"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"}]}