ServiceNow has issued crucial security patches to mitigate a significant vulnerability in its artificial intelligence platform. This action follows the publication of a proof of concept by researchers, demonstrating how the flaw could be exploited to execute remote code without prior authentication.
Details of the Vulnerability
The vulnerability, identified as CVE-2026-6875, involves a sandbox escape that allows attackers to execute code within susceptible ServiceNow instances. The flaw was highlighted in a technical report by Searchlight Cyber’s Assetnote team, titled “Smashing the ServiceNow Sandbox: Pre-Authentication RCE.”
According to the researchers, exploiting the vulnerability could lead to a complete breach of a ServiceNow instance. This includes unauthorized access to stored data, the creation of administrative accounts, and command execution on connected MID Server proxy systems.
ServiceNow’s Response
ServiceNow acknowledged the vulnerability in advisory KB3137947, dated July 13, 2026, confirming its impact on the ServiceNow AI platform. The company has implemented protections for hosted instances and distributed updates to self-hosted customers and partners. At present, no active exploitation has been detected in the wild.
The public proof of concept exploits the GlideRecord query API of the platform, which is integral to data retrieval and processing within ServiceNow applications. Researchers found certain application paths that processed user inputs in ways that could lead to unauthorized code execution.
Exploitation Techniques and Mitigation
Although ServiceNow employs a restricted script sandbox to block unsafe operations, Assetnote discovered a method to circumvent these restrictions via the platform’s script-include mechanism. The researchers identified that the gs.include() function allowed script libraries to be executed in a less restrictive environment.
By altering global JavaScript objects and properties, attackers could execute code beyond the sandbox’s limitations. This method permitted access to database functions, administrative capabilities, and interactions with MID Servers, which connect cloud instances with internal systems, potentially amplifying the impact of a breach.
The vulnerability was reported to ServiceNow on April 1, 2026. Within 24 hours, the company implemented an initial cloud-side mitigation by blocking modifications to critical JavaScript functions. Subsequent updates addressed the sandbox’s inherent weaknesses, and new Guarded Script protections were introduced to limit the scope of potential attacks.
ServiceNow has resolved CVE-2026-6875 in several patches, including Brazil EA and GA, Australia Patch 2, Zurich Patch 7b and 9, and Yokohama Patch 12 Hot Fix 1b and Patch 13. Customers are urged to ensure their instances are updated and to review any incompatible scripts following these upgrades.
Strengthen your security operations center by enhancing threat detection and enabling rapid investigations. Integrate ANY.RUN with your SOC today.
