Sandbox Escape Vulnerability in ServiceNow Now Platform
CVE-2026-6876
8.7HIGH
What is CVE-2026-6876?
ServiceNow has addressed a critical security issue within the Now Platform that permitted a sandbox escape, allowing unauthenticated users to potentially execute arbitrary code. This vulnerability posed a risk of unauthorized access and excessive permissions within the platform. A security update has been rolled out to hosted instances, and users are urged to apply the latest patches or upgrade to secure versions to mitigate any threats stemming from this vulnerability.
Affected Version(s)
Now Platform 0
Now Platform 0
Now Platform 0
