PT-2026-57852 · Servicenow · Servicenow Ai Platform
CVE-2026-6875
·
Published
2026-07-13
·
Updated
2026-09-12
CVSS v4.0
9.5
Critical
| Vector | AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
ServiceNow AI Platform (affected versions not specified)
Description
A critical pre-authentication sandbox-escape flaw exists in the ServiceNow AI Platform. This issue allows an unauthenticated attacker to bypass the platform's sandbox environment and execute arbitrary code remotely. The attack chain involves the use of
GlideRecord, JavaScript evaluation, and Script Includes. Specifically, attackers have been observed targeting the /assessment thanks.do endpoint to achieve code execution. The platform is widely used, powering over 100,000 enterprise AI applications and serving 85% of Fortune 500 companies. Although the vendor initially stated no knowledge of active exploitation, threat intelligence researchers have confirmed in-the-wild attacks occurring shortly after the release of patches for self-hosted instances.Recommendations
Upgrade to a patched release immediately.
Monitor requests for anomalous activity.
Review the Guarded Script protections.
For instances created before September 2024, disable the sandbox enabled setting for any Client Callable Script Includes (Glide AJAX Enabled) unless specifically required.
Fix
RCE
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Servicenow Ai Platform