ZeroHour

CVE-2026-6876

large

Unauthenticated Sandbox Escape Allows Code Execution in ServiceNow AI Platform

CVSS 4.0
10.0 critical
EPSS
<1%p34
Published
()
Modified
AI analysis

CVE-2026-6876 is a sandbox escape in the ServiceNow AI Platform (CWE-94, CWE-693, CWE-1284) that allows an unauthenticated, network-based attacker to execute arbitrary code within the platform. Triggering requires no privileges and no user interaction, consistent with the CVSS 4.0 base of 10.0 (AV:N/PR:N/UI:N with high impact across confidentiality, integrity, and availability). Successful exploitation grants arbitrary code execution inside the platform and potentially more access to the ServiceNow AI Platform than intended. All deployments of the ServiceNow AI Platform are affected: ServiceNow has already deployed the remediation to its hosted (SaaS) instances and has provided the update to partners and self-hosted customers. ServiceNow is not currently aware of malicious exploitation, and no public proof-of-concept is known.

What to do: Self-hosted customers and partners should promptly apply the ServiceNow-provided security update or upgrade to a patched release, prioritizing internet-facing instances given unauthenticated network exploitability. Hosted (SaaS) customers should verify with ServiceNow that their instance was automatically remediated. No workarounds or public PoC are known; consult ServiceNow PSIRT advisories for the specific patched version numbers, which are not included in the source data.

Affected
ServiceNow AI Platform
Estimated exposure
large≈ tens of thousands of ServiceNow instances (hosted instances already centrally patched) — ServiceNow serves on the order of 7,000–8,000 enterprise customers, most of whom run multiple hosted instances (reached by public scans in the tens of thousands and already patched by ServiceNow), while self-hosted and partner deployments…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

ServiceNow has remediated a sandbox escape security issue that was identified in the ServiceNow AI Platform. This security issue could allow an unauthenticated user to execute arbitrary code within the ServiceNow AI Platform, potentially leading to more access to the ServiceNow AI Platform than intended. ServiceNow deployed a security update to hosted instances and ServiceNow provided the update to our partners and self-hosted customers. We are not currently aware of malicious exploitation against ServiceNow instances. We recommend customers promptly apply appropriate updates or upgrade to a patched release if they have not already done so.

Weakness
CWE-94, CWE-693, CWE-1284
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

Three CVSS 10.0 ServiceNow Flaws Could Let Unauthenticated Attackers Execute Code and SQL

ServiceNow patched four AI Platform flaws, including three pre-authentication CVSS 10.0 issues enabling unauthenticated code execution, SQL injection, and privilege escalation.

ServiceNow released patches on August 27, 2026 for four AI Platform flaws: CVE-2026-18885 (code injection in the GraphQL Composite Data API), CVE-2026-18886 (improper access control enabling privilege escalation), and CVE-2026-74820 (SQL injection), all self-rated CVSS 10.0 and exploitable without authentication, plus CVE-2026-6876, an 8.7 sandbox escape. Updates were deployed to hosted instances, but self-hosted customers must patch affected Xanadu, Yokohama, Zurich, and Australia release lines themselves. ServiceNow says it is not aware of exploitation of the new flaws, and no public exploit code existed as of August 28, 2026; separately, Defused reported in-the-wild exploitation of the earlier CVE-2026-6875 (CVSS 9.5), later noting the captured payload matched Searchlight Cyber's PoC.

The Hacker News · 18d agoVulnerability in the wildCVE-2026-18885CVE-2026-18886CVE-2026-74820+2 CVEs