CVE-2026-16723 PUBLISHED

Remote Code Execution in fastjson 1.2.68–1.2.83

Assigner: alibaba
Reserved: 23.07.2026 Published: 23.07.2026 Updated: 23.07.2026

A remote code execution (RCE) vulnerability exists in fastjson 1.2.68 through 1.2.83. This vulnerability is exploitable under fastjson's stock default configuration — no AutoType enablement required, no classpath gadget required.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
CVSS Score: 9

Product Status

Vendor Alibaba
Product Fastjson
Versions Default: unaffected
  • affected from 1.2.68 to 1.2.83 (incl.)

Credits

  • Kirill Firsov of FearsOff Cybersecurity finder

References

Problem Types

  • CWE-20 Improper input validation CWE
  • CWE-502 Deserialization of untrusted data CWE

Impacts

  • CAPEC-586 Object Injection