Remote Code Execution Vulnerability in fastjson by Alibaba
CVE-2026-16723

9CRITICAL

Key Information:

Vendor

Alibaba

Status
Vendor
CVE Published:
23 July 2026

What is CVE-2026-16723?

A remote code execution vulnerability exists in fastjson versions 1.2.68 to 1.2.83, allowing attackers to execute arbitrary code remotely without the need for AutoType enablement or classpath gadgets. This vulnerability can be exploited in the default configuration, which poses a significant risk to applications relying on this library. It is crucial for developers and system administrators to apply the appropriate patches and follow security best practices to safeguard their systems against potential exploitation.

Affected Version(s)

Fastjson 1.2.68 <= 1.2.83

References

CVSS V3.1

Score:
9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Kirill Firsov of FearsOff Cybersecurity
.