Impact
The vulnerability allows an unauthenticated user to execute arbitrary code within the ServiceNow AI Platform, potentially granting elevated privileges beyond intended access. This sandbox escape can be leveraged to run commands, modify data, or create backdoors, compromising confidentiality, integrity, and availability of the platform. The weakness is a form of remote code execution via elevation of privilege and aligns with the following common weaknesses: CWE-1284, CWE-693, CWE-94.
Affected Systems
The affected product is ServiceNow AI Platform, impacting both hosted (cloud) instances and self‑hosted deployments. Partners and customers that have not applied the latest supported release may remain vulnerable. No specific version ranges are listed in the CNA data.
Risk and Exploitability
With a CVSS base score of 10 the vulnerability is considered high severity. The EPSS score is less than 1%, indicating a very low probability of exploitation, further evidenced by its absence from the CISA KEV catalog and lack of known attacks. The likely attack vector is through the platform’s web interface or API, where an unauthenticated user can exploit the sandbox bypass to gain unauthorized code execution and subsequently elevate privileges. The absence of reported exploits does not reduce the risk; the high impact warrants swift remediation.
OpenCVE Enrichment