CVE-2026-6875

CRITICAL EXPLOITED NUCLEI

Sandbox Escape in ServiceNow AI Platform

Title source: cna
STIX 2.1

Exploitation Summary

CVE-2026-6875 has been observed exploited in the wild (reported by VulnCheck KEV). EIP tracks 2 public exploits from researchers including tc4dy, HORKimhab. A Nuclei detection template is also available.

AI-analyzed exploit summary The repository contains only a LICENSE file with no actual exploit code, technical details, or vulnerability analysis. It is a placeholder with no functional content related to CVE-2026-6875.

Description

ServiceNow has addressed a remote code execution vulnerability that was identified in the ServiceNow AI platform. This vulnerability could enable an unauthenticated user, in certain circumstances, to execute code within the ServiceNow platform. ServiceNow addressed this vulnerability by deploying a security update to hosted instances. Relevant security updates have also been provided to ServiceNow self-hosted customers and partners. Further, the vulnerability is addressed in the listed patches and family releases, which have been made available to hosted and self-hosted customers, as well as partners. We are not currently aware of exploitation against ServiceNow instances. We recommend customers promptly apply appropriate updates or upgrade to a patched release if they have not already done so.

Exploits (2)

github STUB
by tc4dy · poc
https://github.com/tc4dy/CVE-2026-6875-PoC-Exploit

The repository contains only a LICENSE file with no actual exploit code, technical details, or vulnerability analysis. It is a placeholder with no functional content related to CVE-2026-6875.

Classification
Stub 99%
Attack Type
Other
Complexity
Trivial
Reliability
Theoretical
Target: unknown
No auth needed
mistral-large-3 · analyzed Jul 21, 2026 Full analysis →
github WORKING POC
by HORKimhab · pythonpoc
https://github.com/HORKimhab/CVE-2026-6875

This PoC exploits CVE-2026-6875, a sandbox escape vulnerability in ServiceNow instances leading to pre-authentication remote code execution (RCE). The exploit leverages a JavaScript sandbox escape via crafted payloads in the `sysparm_assessable_type` parameter to achieve arbitrary JavaScript execution in the global scope.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: ServiceNow (vulnerable versions up to 2026)
No auth needed
Prerequisites: Network access to a vulnerable ServiceNow instance · Target endpoint must be `/assessment_thanks.do` · Optional: Collaborator URL for callback verification
mistral-large-3 · analyzed Jul 21, 2026 Full analysis →

Nuclei Templates (1)

ServiceNow AI Platform - Pre-Auth JavaScript Sandbox Escape RCE
CRITICALVERIFIEDby pdteam,DhiyaneshDk
Shodan: http.favicon.hash:"1701804003" || http.title:"servicenow"
FOFA: icon_hash=1701804003 || title="servicenow"

Scores

CVSS v4 9.5
EPSS 0.2449
EPSS Percentile 97.7%
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

VulnCheck KEV 2026-07-18
CWE
CWE-94
Status published
Products (7)
ServiceNow/ServiceNow AI Platform < Australia Patch 2
ServiceNow/ServiceNow AI Platform < Brazil EA
ServiceNow/ServiceNow AI Platform < Brazil GA
ServiceNow/ServiceNow AI Platform < Yokohama Patch 12 Hot Fix 1b
ServiceNow/ServiceNow AI Platform < Yokohama Patch 13
ServiceNow/ServiceNow AI Platform < Zurich Patch 7b
ServiceNow/ServiceNow AI Platform < Zurich Patch 9
Published Jul 13, 2026
Tracked Since Jul 14, 2026