Public PoC released for Critical ServiceNow Sandbox RCE Vulnerability
ID: 7eed7cc9-830b-5ac3-8053-9293f76a4dc6
STIX ID: report--7eed7cc9-830b-5ac3-8053-9293f76a4dc6
Feed Name: cybersecurityNews.com
ServiceNow disclosed and patched a critical pre-authentication sandbox-escape vulnerability (CVE-2026-6875) in its AI platform after Searchlight Cyber published a PoC showing how specially crafted GlideRecord queries and misuse of gs.include() can bypass the restricted script sandbox to achieve remote code execution; successful exploitation could lead to full instance compromise (data access, admin account creation) and interaction with MID Servers. ServiceNow applied cloud-side mitigations, released fixes for affected releases, introduced Guarded Script protections, and reports no known active exploitation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
