Remote Code Execution Vulnerability in ServiceNow AI Platform
CVE-2026-0542
Key Information:
- Vendor
Servicenow
- Status
- Vendor
- CVE Published:
- 25 February 2026
Badges
What is CVE-2026-0542?
A potential vulnerability exists in the ServiceNow AI Platform, which may allow an unauthenticated user to execute arbitrary code in the ServiceNow Sandbox under specific conditions. ServiceNow has released security updates to address this issue for both hosted and self-hosted customers. Users are encouraged to apply the security updates quickly to mitigate any risks associated with this vulnerability, although there are no current reports of exploitation affecting customer environments.
Affected Version(s)
ServiceNow AI Platform 0
ServiceNow AI Platform 0
ServiceNow AI Platform 0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
