PT-2026-82729 · Servicenow · Now Platform
CVSS v4.0
10
Critical
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
Now Platform (affected versions not specified)
Description
A sandbox escape issue exists in the Now Platform. This flaw allows an unauthenticated user to execute arbitrary code, which could result in unauthorized access to the platform beyond intended permissions. A sandbox is a security mechanism for separating running programs from the rest of the system to prevent malicious code from affecting the host.
Recommendations
Apply the security updates provided by ServiceNow or upgrade to a patched release.
Fix
Protection Mechanism Failure
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Now Platform