PT-2026-57852 · Servicenow · Servicenow Ai Platform

CVE-2026-6875

·

Published

2026-07-13

·

Updated

2026-07-21

CVSS v4.0

9.5

Critical

VectorAV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions ServiceNow AI Platform (affected versions not specified)
Description An unauthenticated remote code execution flaw exists in the ServiceNow AI Platform due to a server-side sandbox escape. The issue involves a novel attack chain utilizing GlideRecord, JavaScript evaluation, and Script Includes to break out of the sandbox environment and execute arbitrary code within the platform. The vulnerability is targeted via the /assessment thanks.do API endpoint. This platform is widely used, powering over 100,000 enterprise AI applications and serving 85% of Fortune 500 companies. Although the vendor initially stated no knowledge of exploitation, threat intelligence researchers have confirmed active in-the-wild attacks using payloads that reach the code-execution primitive through routes different from published proofs-of-concept.
Recommendations Upgrade to a patched release immediately. Review the new Guarded Script protections. Monitor requests for anomalous activity.

Fix

RCE

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-6875

Affected Products

Servicenow Ai Platform