Description
ServiceNow has addressed a remote code execution vulnerability that was identified in the ServiceNow AI platform. This vulnerability could enable an unauthenticated user, in certain circumstances, to execute code within the ServiceNow platform.


ServiceNow addressed this vulnerability by deploying a security update to hosted instances. Relevant security updates have also been provided to ServiceNow self-hosted customers and partners.




Further, the vulnerability is addressed in the listed patches and family releases, which have been made available to hosted and self-hosted customers, as well as partners. We are not currently aware of exploitation against ServiceNow instances.




We recommend customers promptly apply appropriate updates or upgrade to a patched release if they have not already done so.
Published: 2026-07-13
Score: 9.5 Critical
EPSS: 24.5% Moderate
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw is a sandbox escape (CWE‑94) that allows an unauthenticated attacker to run arbitrary code inside the ServiceNow AI Platform. This remote code execution could grant full control over the application environment, enabling the attacker to read, modify, or delete data and potentially pivot to other systems.

Affected Systems

Any deployment of the ServiceNow AI Platform, whether hosted by ServiceNow or self‑hosted on customer premises, is affected. The fix has been released for all hosted instances and for self‑hosted customers and partners through specific security updates or family releases.

Risk and Exploitability

The CVSS score of 9.5 marks it as critical. The EPSS score of 24% and its absence from CISA's KEV catalog indicate a significant current exploitation likelihood, but the vulnerability could still be exploited if a suitable attack vector was discovered. The attack vector is suspected to be an unauthenticated request to the AI Platform’s API or interface, though that is inferred from the description.

Generated by OpenCVE AI on July 31, 2026 at 11:25 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the ServiceNow security update released for the AI Platform to all hosted and self‑hosted instances.
  • If your self‑hosted version has not yet received the patch, deploy the latest ServiceNow family release that contains the fix as soon as it becomes available.
  • Until the update is applied, isolate the AI Platform services from external traffic or restrict access to trusted IP ranges.

Generated by OpenCVE AI on July 31, 2026 at 11:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 13 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-94
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 13 Jul 2026 19:45:00 +0000

Type Values Removed Values Added
First Time appeared Servicenow
Servicenow servicenow Ai Platform
Vendors & Products Servicenow
Servicenow servicenow Ai Platform

Mon, 13 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Description ServiceNow has addressed a remote code execution vulnerability that was identified in the ServiceNow AI platform. This vulnerability could enable an unauthenticated user, in certain circumstances, to execute code within the ServiceNow platform. ServiceNow addressed this vulnerability by deploying a security update to hosted instances. Relevant security updates have also been provided to ServiceNow self-hosted customers and partners. Further, the vulnerability is addressed in the listed patches and family releases, which have been made available to hosted and self-hosted customers, as well as partners. We are not currently aware of exploitation against ServiceNow instances. We recommend customers promptly apply appropriate updates or upgrade to a patched release if they have not already done so.
Title Sandbox Escape in ServiceNow AI Platform
References
Metrics cvssV4_0

{'score': 9.5, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}


Subscriptions

Servicenow Servicenow Ai Platform
cve-icon MITRE

Status: PUBLISHED

Assigner: SN

Published:

Updated: 2026-07-14T03:55:45.828Z

Reserved: 2026-04-22T18:21:24.368Z

Link: CVE-2026-6875

cve-icon Vulnrichment

Updated: 2026-07-13T18:57:10.817Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T11:30:05Z

Weaknesses
  • CWE-94

    Improper Control of Generation of Code ('Code Injection')