Alibaba Fastjson 1.2.68 < 1.2.84 RCE (CVE-2026-16723)

critical Nessus Plugin ID 331911

Synopsis

A JSON library installed on the remote host is affected by a remote code execution vulnerability.

Description

The version of Alibaba Fastjson installed on the remote host is 1.2.68 through 1.2.83. It is, therefore, affected by a remote code execution vulnerability:

- A remote code execution (RCE) vulnerability exists in fastjson 1.2.68 through 1.2.83. This vulnerability is exploitable under fastjson's stock default configuration - no AutoType enablement required, no classpath gadget required. (CVE-2026-16723)

Enabling SafeMode (-Dfastjson.parser.safeMode=true, ParserConfig.getGlobalInstance().setSafeMode(true), or fastjson.properties) or switching to a noneautotype build (e.g. com.alibaba:fastjson:1.2.83_noneautotype) mitigates this issue without upgrading. Nessus cannot verify the runtime SafeMode configuration, so this finding is flagged as a potential vulnerability.

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.

Solution

Upgrade to Alibaba Fastjson version 1.2.84 or later. Alternatively, enable SafeMode (-Dfastjson.parser.safeMode=true) or switch to a noneautotype build.

See Also

http://www.nessus.org/u?c5dabecd

Plugin Details

Severity: Critical

ID: 331911

File Name: alibaba_fastjson_CVE-2026-16723.nasl

Version: 1.1

Type: Local

Agent: windows, macosx, unix

Family: Misc.

Published: 8/4/2026

Updated: 8/4/2026

Configuration: Enable paranoid mode

Supported Sensors: Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: Critical

Score: 9.5

Percentile: 99.86

CVSS v2

Risk Factor: High

Base Score: 7.6

Vector: CVSS2#AV:N/AC:H/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2026-16723

CVSS v3

Risk Factor: Critical

Base Score: 9

Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H

Vulnerability Information

CPE: cpe:/a:alibaba:fastjson

Required KB Items: installed_sw/Alibaba Fastjson, Settings/ParanoidReport

Patch Publication Date: 7/21/2026

Vulnerability Publication Date: 7/21/2026

Reference Information

CVE: CVE-2026-16723