CVE Watchtower


← Back to CVE List

CVE-2026-16723NVD

Vulnerability Summary

A remote code execution (RCE) vulnerability exists in fastjson 1.2.68 through 1.2.83. This vulnerability is exploitable under fastjson's stock default configuration — no AutoType enablement required, no classpath gadget required.
Severity Level
CRITICAL(9.0)
Published Date
Jul 23, 2026
Last Modified
Jul 23, 2026
Exploitation Status
No confirmed exploitation yet
EPSS Score (30-Day)
0.41%Probability
Root Weakness (CWE)
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required.
CVSS v3.1 Base Metrics
Attack VectorNetwork
Attack ComplexityHigh
Privileges RequiredNone
User InteractionNone
ScopeChanged
ConfidentialityHigh
IntegrityHigh
AvailabilityHigh