PT-2026-57852 · Servicenow · Servicenow Ai Platform
CVE-2026-6875
·
Published
2026-07-13
·
Updated
2026-07-21
CVSS v4.0
9.5
Critical
| Vector | AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
ServiceNow AI Platform (affected versions not specified)
Description
An unauthenticated remote code execution flaw exists in the ServiceNow AI Platform due to a server-side sandbox escape. The issue involves a novel attack chain utilizing
GlideRecord, JavaScript evaluation, and Script Includes to break out of the sandbox environment and execute arbitrary code within the platform. The vulnerability is targeted via the /assessment thanks.do API endpoint. This platform is widely used, powering over 100,000 enterprise AI applications and serving 85% of Fortune 500 companies. Although the vendor initially stated no knowledge of exploitation, threat intelligence researchers have confirmed active in-the-wild attacks using payloads that reach the code-execution primitive through routes different from published proofs-of-concept.Recommendations
Upgrade to a patched release immediately.
Review the new Guarded Script protections.
Monitor requests for anomalous activity.
Fix
RCE
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Servicenow Ai Platform