Missing authorization checks in the Predicates API may allow a malicious client to execute arbitrary code on a Hazelcast member.
Enterprise customers should upgrade to a fixed version of Hazelcast Enterprise Edition:
Customers with extended support contracts should contact Hazelcast Support for information on patches for older versions.
Community Edition users should upgrade to version 5.7.0.
None - customers are advised to upgrade to a fixed version as soon as possible.
{
"cwe_ids": [
"CWE-862"
],
"github_reviewed": true,
"github_reviewed_at": "2026-10-08T22:09:34Z",
"nvd_published_at": null,
"severity": "HIGH"
}