CVE-2026-107725High▾ TwilightHazelcast is a unified real-time data platform combining stream processing with a fast data store. Prior to 5.4.5, 5.5.10, and 5.6.1, missing authorization checks in the IMap Predicates API allow a malicious client with limited privilege…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Hazelcast is a unified real-time data platform combining stream processing with a fast data store. Prior to 5.4.5, 5.5.10, and 5.6.1, missing authorization checks in the IMap Predicates API allow a malicious client with limited privileges to execute arbitrary code on a Hazelcast cluster member. This issue is fixed in versions 5.4.5, 5.5.10, 5.6.1, and 5.7.0.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Affected packages:
com.hazelcast:hazelcast = 5.6.0com.hazelcast:hazelcast >= 5.5.0, < 5.5.10com.hazelcast:hazelcast < 5.4.5Patched in:
com.hazelcast:hazelcast 5.7.0com.hazelcast:hazelcast 5.7.0com.hazelcast:hazelcast 5.7.0Connected by shared product, vendor, weakness, or advisory.
CVE-2026-107726CriticalHazelcast is a unified real-time data platform combining stream processing with a fast data store
CVE-2025-12924Medium· 4.3A vulnerability was identified in rymcu forest up to de53ce79db9faa2efc4e79ce1077a302c42a1224
CVE-2024-0829Medium· 4.3The Comments Extra Fields For Post,Pages and CPT plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 5.0
CVE-2025-13772High· 7.1GitLab has remediated an issue in GitLab EE affecting all versions from 18.4 before 18.5.5, 18.6 before 18.6.3, and 18.7 before 18.7.1 that could have allowed an authenticated user to access and utilize AI model settings from unauthorize…
CVE-2025-32781Medium· 6.5Apollo is a reliable configuration management system suitable for microservice configuration management scenarios
CVE-2025-10212Medium· 5.3The SiteAlert (Formerly WP Health) plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on multiple functions in all versions up to, and including, 1.9.8