Vulnerability GHSA-w294-6q5q-53p8
High Risk
HIGH RISK
CVSS Score: 8.0
Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
9 hours ago
October 08, 2026 at 10:09 PM UTC
Hazelcast has an authorization bypass in IMap Predicates API
1.6.0 - 1.7.1 and 1.9.3 - 1.9.4 and 2.2.0 - 2.5.1 and 3.4.8 and 3.9.4 and 3.11.0 - 3.12.1 and 3.12.10 - 3.12.13 and 5.4.0 - 5.6.0
1.6.0 - 1.7.1 and 1.9.3 - 1.9.4 and 2.2.0 - 2.5.1 and 3.4.8 and 3.9.4 and 3.11.0 - 3.12.1 and 3.12.10 - 3.12.13 and 5.4.0 - 5.6.0
Summary
Hazelcast has an authorization bypass in IMap Predicates API
Details
Impact
Missing authorization checks in the Predicates API may allow a malicious client to execute arbitrary code on a Hazelcast member.
Patches
Enterprise customers should upgrade to a fixed version of Hazelcast Enterprise Edition:
- 5.7.0
- 5.6.1
- 5.5.10
- 5.4.5
Customers with extended support contracts should contact Hazelcast Support for information on patches for older versions.
Community Edition users should upgrade to version 5.7.0.
Workarounds
None - customers are advised to upgrade to a fixed version as soon as possible.
Related Vulnerabilities
Other vulnerabilities affecting the same packages
Critical
9 hours ago
Hazelcast allows arbitrary member memory access by low-privileged client
1.6.0 - 1.7.1 and 1.9.3 - 1.9.4 and 2.2.0 - 2.5.1 and 3.4.8 and 3.9.4 and 3.11.0 - 3.12.1 and 3.12.10 - 3.12.13 and 5.4.0 - 5.6.0 GHSA-6v25-8wq6-xq4j
1.6.0 - 1.7.1 and 1.9.3 - 1.9.4 and 2.2.0 - 2.5.1 and 3.4.8 and 3.9.4 and 3.11.0 - 3.12.1 and 3.12.10 - 3.12.13 and 5.4.0 - 5.6.0 GHSA-6v25-8wq6-xq4j
High Risk
2 years ago
Missing permission checks on Hazelcast client protocol
1.6.0 - 1.7.1 and 1.9.3 - 1.9.4 and 2.2.0 - 2.5.1 and 5.3.4 GHSA-xh6m-7cr7-xx66
1.6.0 - 1.7.1 and 1.9.3 - 1.9.4 and 2.2.0 - 2.5.1 and 5.3.4 GHSA-xh6m-7cr7-xx66
Medium Risk
2 years ago
Hazelcast Platform permission checking in CSV File Source connector
1.6.0 - 1.7.1 and 1.9.3 - 1.9.4 and 2.2.0 - 2.5.1 and 3.12.0 - 3.12.1 and 5.3.4 GHSA-8h4x-xvjp-vf99
1.6.0 - 1.7.1 and 1.9.3 - 1.9.4 and 2.2.0 - 2.5.1 and 3.12.0 - 3.12.1 and 5.3.4 GHSA-8h4x-xvjp-vf99
High Risk
3 years ago
Hazelcast Executor Services don't check client permissions properly
1.6.0 - 1.7.1 and 1.9.3 - 1.9.4 and 2.2.0 - 2.5.1 and 3.12.0 - 3.12.1 GHSA-c5vj-wp4v-mmvx
1.6.0 - 1.7.1 and 1.9.3 - 1.9.4 and 2.2.0 - 2.5.1 and 3.12.0 - 3.12.1 GHSA-c5vj-wp4v-mmvx
Medium Risk
3 years ago
Hazelcast vulnerable to unmasked password exposure
5.3.0 GHSA-5gj6-62g7-vmgf
5.3.0 GHSA-5gj6-62g7-vmgf
Impacted packages
Timeline
Published
9 hours ago
October 08, 2026 at 10:09 PM UTC
Fixed (5.7.0)
Unknown
Unknown
Last Modified
8 hours ago
October 08, 2026 at 10:30 PM UTC