Sandbox Escape Vulnerability in ServiceNow Now Platform
CVE-2026-6876
10CRITICAL
What is CVE-2026-6876?
ServiceNow has addressed a critical security issue within the Now Platform that permitted a sandbox escape, allowing unauthenticated users to potentially execute arbitrary code. This vulnerability posed a risk of unauthorized access and excessive permissions within the platform. A security update has been rolled out to hosted instances, and users are urged to apply the latest patches or upgrade to secure versions to mitigate any threats stemming from this vulnerability.
Affected Version(s)
ServiceNow AI Platform 0
ServiceNow AI Platform 0
ServiceNow AI Platform 0
