Unauthenticated code execution via filter sandbox escape
Published Jul 13, 2026 · Updated Jul 13, 2026
Code injection in ServiceNow AI Platform allows remote attackers to execute arbitrary platform code without authentication. The assessment_thanks.do page passes sysparm_assessable_type to GlideRecord.addQuery, which evaluates javascript-prefixed filter values; an attacker can replace protected JavaScript properties and abuse gs.include to invoke Function outside the restricted sandbox. Reachability requires network access to the unauthenticated page, and successful exploitation grants control of platform data and configured MID servers.
Summary
What happened
Code injection in ServiceNow AI Platform allows remote attackers to execute arbitrary platform code without authentication. The assessment_thanks.do page passes sysparm_assessable_type to GlideRecord.addQuery, which evaluates javascript-prefixed filter values; an attacker can replace protected JavaScript properties and abuse gs.include to invoke Function outside the restricted sandbox. Reachability requires network access to the unauthenticated page, and successful exploitation grants control of platform data and configured MID servers.
The record
- CVE
- CVE-2026-6875
- Published
- Jul 13, 2026
- Updated
- Jul 13, 2026
- Vendor
- ServiceNow
- Product
- ServiceNow AI Platform
- Classifications
- CWE-94, T1190
- Attack vector
- network
- Privileges
- unauthenticated
Timeline
How it unfolded
- Jul 13, 2026CVE publishedPublication date reported by the CVE source.
- Jul 13, 2026Record updatedLatest update available in the CVE record.
Exploitability
Present is not the same as exploitable
Compare your product and version with the public record. A matching version still requires validation against your environment.
Is a vulnerable build present?
Compare these published version ranges with your installed build and any vendor patches.
- Affected versionversion=0 <Australia Patch 2
- Affected versionversion=0 <Brazil EA
- Affected versionversion=0 <Brazil GA
- Affected versionversion=0 <Yokohama Patch 12 Hot Fix 1b
- Affected versionversion=0 <Yokohama Patch 13
- Affected versionversion=0 <Zurich Patch 7b
- Affected versionversion=0 <Zurich Patch 9
What conditions does exploitation require?
What is affected?
Published CVSS scores
CVSS describes severity. EPSS estimates exploitation probability.
Attacks
What attackers are doing with it
Daily unique IPs observed by Shadowserver honeypots for known exploited vulnerabilities (KEVs). Missing observations do not establish an absence of attacks.
Weakness, pattern, technique
Public exploit references
- tc4dy ServiceNow pre-auth RCE frameworkweaponized · unverified
- Searchlight Cyber sandbox-escape proof of conceptproof of concept · demonstrated
- ProjectDiscovery CVE-2026-6875 Nuclei templatefunctional · validated
Labels summarize the accepted research assessment. They do not indicate a test against your environment.
Reported exploitation
- In-the-wild exploitation reported by Defusedreported exploitation
Technologies
Your stack
See the directory against your own environment.
Your stack
Check the software in your environment
Book a demo to see how Hinoki identifies affected software and validates exploitability in your environment.
Book a demo