CVE-2026-107725: Hazelcast has an authorization bypass in IMap Predicates API
### Impact Missing authorization checks in the [Predicates API](https://docs.hazelcast.com/hazelcast/5.7/query/predicate-overview) may allow a malicious client to execute arbitrary code on a Hazelcast member. ### Patches Enterprise customers should upgrade to a fixed version of Hazelcast Enterprise Edition: * 5.7.0 * 5.6.1 * 5.5.10 * 5.4.5 Customers with extended support contracts should contact Hazelcast Support for information on patches for older versions. Community Edition users should upgrade to version 5.7.0. ### Workarounds None - customers are advised to upgrade to a fixed version as soon as possible.
Recommended action
Recommended action
Upgrade affected packages to a patched version: com.hazelcast:hazelcast 5.7.0, com.hazelcast:hazelcast 5.7.0, com.hazelcast:hazelcast 5.7.0.
Technical details
- Vendor
- Not specified
- Product
- com.hazelcast:hazelcast
- Exploitation
- none known
- Evidence
- official
Evidence and sources
This record is attributed to GitHub Advisories. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.
Open primary source