A critical vulnerability identified in the ServiceNow platform, labeled CVE-2026-6875, is being actively exploited by attackers. This flaw enables unauthorized individuals to bypass security measures and execute code on compromised systems without needing valid user credentials.
Understanding the ServiceNow Vulnerability
The vulnerability is specifically associated with the ServiceNow AI Platform and is characterized as a pre-authentication sandbox escape. Essentially, attackers can potentially exploit this flaw without possessing a legitimate ServiceNow account, posing a significant security risk to affected systems.
ServiceNow has acknowledged that this issue could permit unauthorized code execution under certain conditions. The vulnerability was initially discovered by security experts at Searchlight Cyber’s Assetnote, who reported it to ServiceNow on April 1, 2026. The flaw allows attacker-controlled inputs to reach server-side GlideRecord query paths, leading to unauthorized JavaScript execution.
Impact and Recommended Actions
The vulnerability is particularly dangerous due to its potential to allow attackers access to sensitive data, create administrator accounts, and execute commands via configured MID Servers or proxy infrastructure. ServiceNow has released security updates for this vulnerability, providing patches for both hosted and self-hosted platforms.
Organizations using self-managed ServiceNow environments are urged to apply the latest security updates or upgrade to a patched version immediately. Implementing Guarded Script is recommended to mitigate sandbox escape attacks by restricting certain JavaScript expressions and constructs in sandboxed environments.
Urgency of Mitigation
The threat intelligence firm Defused has confirmed that this vulnerability is being exploited in the wild, highlighting the urgency for immediate mitigation. Initially, ServiceNow reported no known exploitation, but subsequent data from Defused revealed that attempts began following public disclosure of the vulnerability.
Security teams are advised to review ServiceNow update status, examine logs for suspicious activities targeting the /assessment_thanks.do endpoint, and scrutinize unexpected administrative account creations and unusual MID Server actions.
This incident emphasizes the risks associated with unauthenticated inputs accessing powerful server-side functions. Given the active exploitation, patching exposed and self-hosted ServiceNow instances should be prioritized to prevent potential incidents.
Ensuring your systems are updated and secure is crucial in the current threat landscape. Organizations must act swiftly to protect themselves from this critical vulnerability.
