PT-2026-82729 · Servicenow · Now Platform

·

CVE-2026-6876

·

Published

2026-08-27

·

Updated

2026-09-01

CVSS v4.0

10

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Now Platform (affected versions not specified)
Description A sandbox escape issue exists in the Now Platform. This flaw allows an unauthenticated user to execute arbitrary code, which could result in unauthorized access to the platform beyond intended permissions. A sandbox is a security mechanism for separating running programs from the rest of the system to prevent malicious code from affecting the host.
Recommendations Apply the security updates provided by ServiceNow or upgrade to a patched release.

Fix

Protection Mechanism Failure

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-6876

Affected Products

Now Platform