loader image
South Asian security engineer in SOC, ServiceNow sandbox flaw alert: Unauthenticated code exec. sticky CVE-2026-6875
ServiceNow Sandbox Flaw Allows Hackers to Run Code

Hackers are actively exploiting a serious ServiceNow sandbox flaw, identified as CVE-2026-6875. This vulnerability allows unauthenticated attackers to escape the script sandbox and execute code on affected systems. Impacting the ServiceNow AI Platform, the flaw is notable because attackers don’t need valid accounts to exploit it. Researchers from Searchlight Cyber’s Assetnote discovered the issue and found attacker-controlled inputs could trigger JavaScript evaluation via the /assessment_thanks.do endpoint.

ServiceNow has issued security updates to address the vulnerability. Companies using self-managed ServiceNow deployments should immediately apply these patches or upgrade to a secure release. Enabling Guarded Script can help mitigate attacks by limiting JavaScript execution within sandboxed environments.

Active exploitation of this flaw underscores the risks of unauthenticated inputs reaching powerful scripting functions. Organizations must prioritize patching exposed instances and regularly inspect logs for suspicious activity. For more detailed information, read the full news article at the link below:

Hackers are Actively Exploiting ServiceNow Vulnerability in the Wild

Write a Reply or Comment

Your email address will not be published. Required fields are marked *