CVE-2020-26168: Hazelcast
Critical severity, CVSS 9.8. EPSS: 1.6% chance of exploitation in the next 30 days.
The LDAP authentication method in LdapLoginModule in Hazelcast IMDG Enterprise 4.x before 4.0.3, and Jet Enterprise 4.x through 4.2, doesn't verify properly the password in some system-user-dn scenarios. As a result, users (clients/members) can be authenticated even if they provide invalid passwords.
Affected products
- Hazelcast Hazelcast: from 4.0, before 4.0.3 (fixed in 4.0.3)
- Hazelcast Jet: from 4.0, up to and including 4.2
Published 2020-11-09. Last modified 2026-06-17.