ServiceNow AI Platform Sandbox Escape Enables Unauthenticated Remote Code Execution (CVE-2026-6875) — Threadlinqs Intelligence
As of 2026-07-22, ServiceNow AI Platform Sandbox Escape Enables Unauthenticated Remote Code Execution (CVE-2026-6875) is a critical-severity vulnerability threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 35 indicators of compromise.
Threat ID: TL-2026-1305 · Severity: CRITICAL · CVSS: 9.5 · Status: ACTIVE · Category: VULNERABILITY
Updated: 2026-07-22 · revalidated 1× · latest source
CVE-2026-6875 is a critical sandbox escape vulnerability (CVSS 4.0: 9.5) in the ServiceNow AI Platform that lets an unauthenticated remote attacker break out of the platform's restricted AI execution
ServiceNow disclosed CVE-2026-6875 on July 13, 2026 via security advisory KB3137947, describing a sandbox escape flaw in the ServiceNow AI Platform's containment layer for AI-driven processes. The AI Platform sandbox is designed to isolate untrusted AI-generated or AI-processed inputs — including workloads run through Now Assist and other embedded generative-AI workflows — from the broader Now Platform application stack; a successful escape breaks that isolation and allows an attacker to execute code directly within the platform. Critically, exploitation requires no authentication, meaning any network-reachable, unpatched instance — hosted or self-hosted — is potentially exposed to unauthenticated remote code execution.
ServiceNow assigned a CVSS 4.0 score of 9.5 (Critical), vector CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H, and mapped the flaw to CWE-94 (Improper Control of Generation of Code / Code Injection), consistent with an AI-generated-code-execution sandbox bypass. The vulnerability was reserved in the CVE program on April 22, 2026 and publicly disclosed on July 13, 2026, with the record updated July 14, 2026. Discovery is credited to security researcher Adam Kues of Assetnote, a researcher with a documented history of ServiceNow vulnerability research (Assetnote's prior published work with Kues covers CVE-2024-4879, CVE-2024-5178, and CVE-2024-5217 — unauthenticated Glide-scripting-language code execution, arbitrary MID Server command execution, and local file read issues in earlier ServiceNow releases).
ServiceNow withheld the specific escape technique and proof-of-concept details from the public advisory — explicitly stating it has not disclosed "technical details about the exploit, attack prerequisites, affected components, or a proof of concept" — an intentional choice to give self-hosted customers a patching window before exploit code could be reverse-engineered from the fix. The vendor states it has no evidence of the flaw being exploited in the wild against customer instances as of the July 13, 2026 disclosure, and CVE-2026-6875 does not appear in the CISA Known Exploited Vulnerabilities catalog as of July 14, 2026.
Security reporting on the flaw characterizes the downstream risk of a successful escape as including unauthorized access to sensitive business data and IT service records, workflow manipulation, credential and API token theft, lateral movement through other enterprise applications connected to the instance, and disruption of IT operations — consistent with an attacker obtaining arbitrary code execution inside a central ITSM/workflow-automation platform that typically holds broad integration credentials and cross-system access.
Affected releases span four ServiceNow release trains: Australia (fixed in Patch 2), Yokohama (fixed in Patch 12 Hot Fix 1b or Patch 13), Zurich (fixed in Patch 7b or Patch 9), and Brazil (fixed as of the Early Access and General Availability releases). ServiceNow has already deployed the fix to all hosted instances; self-hosted and partner-hosted customers must apply the corresponding patch manually. Supplementary guidance was published under KB2930717 and KB2930740. This is the second unauthenticated RCE disclosed against the ServiceNow AI Platform's sandbox in 2026: the first, CVE-2026-0542 (CWE-653, CVSS 4.0 9.8), was proactively patched on hosted instances on January 6, 2026 ahead of public disclosure and involved a distinct root cause reported as a prototype-pollution vector combined with an overlooked Java-backend reflection path, affecting the Zurich, Yokohama, and Xanadu release trains. Two critical, unauthenticated sandbox-escape RCEs against the same AI Platform containment layer within roughly six months underscores that layer as a recurring high-value target for vulnerability research.
Target sectors: government administration, finance, health, technology, manufacturing, retail, telecoms, education
Target regions: North America, Europe, Asia Pacific, Global
Detections & IOCs
As of 2026-07-26, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 35 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
VULNERABILITY, CRITICAL, threat intelligence, cybersecurity, CVE-2026-6875, T1595.002, T1588.005, T1190, T1059, T1059.007, T1505.003, T1068, T1611, T1211, T1528