CVE-2026-16723
A remote code execution (RCE) vulnerability exists in fastjson 1.2.68 through 1.2.83. This vulnerability is exploitable under fastjson's stock default configuration — no AutoType enablement required, no classpath gadget required.
- Affected products
- Spring Boot, Fastjson
- Fix
- Available
- CVSS 3.1
- 9.0 CRITICAL
- EPSS
- 16.0% (97th percentile)
- Weakness
- CWE-20, CWE-502
- NVD status
- Deferred
- Published
- 2026-07-23
- Attack patterns
- CAPEC-586
- Entry point
- keyword request body
- Path
- api/products/search
CVE-2026-16723 at NVD
17 known exploits for CVE-2026-16723
Proof-of-concept code and exploit modules indexed by Sploitus
CVE-2026-16723
fastjson-cve
fastjson-rce-lab
CVE-2026-16723 — Updated!
CVE-2026-16723
CVE-2026-16723
CVE-2026-16723
CVE-2026-16723
CVE-2026-16723
Exploit for CVE-2026-16723
Exploit for CVE-2026-16723
Exploit for CVE-2026-16723
Exploit for CVE-2026-16723
CVE-2026-16723 — Updated!
Exploit for CVE-2026-16723
Exploit for CVE-2026-16723
Exploit for CVE-2026-16723