Sandbox Escape Vulnerability in ServiceNow Now Platform
CVE-2026-6876

8.7HIGH

Key Information:

Vendor

Servicenow

Vendor
CVE Published:
27 August 2026

What is CVE-2026-6876?

ServiceNow has addressed a critical security issue within the Now Platform that permitted a sandbox escape, allowing unauthenticated users to potentially execute arbitrary code. This vulnerability posed a risk of unauthorized access and excessive permissions within the platform. A security update has been rolled out to hosted instances, and users are urged to apply the latest patches or upgrade to secure versions to mitigate any threats stemming from this vulnerability.

Affected Version(s)

Now Platform 0

Now Platform 0

Now Platform 0

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Paul Alkemade
.