S4E just found a high webmin panel detection scanner
critical·Product Based Web Vulnerabilities·Updated Jul 22, 2026

CVE-2026-6875 Scanner

CVE-2026-6875 Scanner - Remote Code Execution (RCE) vulnerability in ServiceNow AI Platform

Est. Time~10 seconds
Scan TypeGroup Scan
Targetsdomain, subdomain, ipv4
CostFree
3.5k
Times Used
continuous scan runs
3.4k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2026-6875
9.5
CVSScritical
Exploitable remotely over the internet · no authentication required.

ServiceNow has addressed a remote code execution vulnerability that was identified in the ServiceNow AI platform. This vulnerability could enable an unauthenticated user, in certain circumstances, to execute code within the ServiceNow platform. ServiceNow addressed this vulnerability by deploying a security update to hosted instances. Relevant security updates have also been provided to ServiceNow self-hosted customers and partners. Further, the vulnerability is addressed in the listed patches and family releases, which have been made available to hosted and self-hosted customers, as well as partners. We are not currently aware of exploitation against ServiceNow instances. We recommend customers promptly apply appropriate updates or upgrade to a patched release if they have not already done so.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
ServiceNow AI Platformby ServiceNow
AFFECTED< Australia Patch 2SAFE ✓≥ Australia Patch 2
Updated Aug 22, 2026View on NVD →
Detail

ServiceNow AI Platform is a popular software utilized by organizations worldwide for automating digital workflows and enhancing service delivery through AI capabilities. This platform is extensively used in industries where efficient process automation is critical to improving service management, IT operations, and customer engagement. ServiceNow is often deployed across various sectors such as healthcare, finance, telecom, and government, allowing users to streamline operations, manage incidents, and facilitate communication between departments. Its robust integration capabilities make it an ideal choice for connecting numerous enterprise applications, ensuring data consistency, and promoting operational efficiency. Due to its expansive use and integration within organizational infrastructures, safeguarding its functionality from vulnerabilities like RCE is paramount to maintaining business continuity.

The Remote Code Execution (RCE) vulnerability described targets the ServiceNow AI Platform by exploiting its JavaScript sandbox escape. Before patching, certain releases like Brazil, Australia, Zurich, and Yokohama were susceptible to unauthorized code execution if accessed by cyber attackers. This vulnerability allows malicious actors to bypass authorization mechanisms, potentially leading to severe security breaches. The flaw lies within the /assessment_thanks.do endpoint, which inadequately handles certain JavaScript-prefixed values allowing them to be executed in an unintended context. Such vulnerabilities are targeted due to their potential to completely compromise control over the affected systems, making them a significant threat when left unpatched.

Technical details of the vulnerability indicate the involvement of the sysparm_assessable_type parameter within the ServiceNow platform. By delivering inputs that exploit the JavaScript sandbox escape, external attackers can manipulate input values like Object.defineProperty and Class.create.constructor. By appending these values through the gs.include('ItemViewElementsProvider') path, attackers can bypass existing sandbox limitations and invoke arbitrary GlideController code execution. This allows the attacker to perform unauthorized operations, which the platform typically restricts, giving them unrestricted command execution capabilities on the system.

Exploitation of this vulnerability poses significant security risks to organizations utilizing the affected ServiceNow releases. Unauthorized code execution can allow attackers to access sensitive data within database tables, alter system settings, and even create administrator accounts. Furthermore, it enables potential shell command execution on connected MID proxy servers, facilitating unauthorized access into internal networks, potentially leading to widespread data breaches, operational disruptions, and financial losses if leveraged effectively by malicious actors.

REFERENCES

Solution Advice
  • Apply all recommended security updates provided by ServiceNow for affected versions.
  • Consult and implement additional hardening strategies outlined in ServiceNow's security best practices.
  • Regularly monitor and evaluate network traffic for unusual activity to detect potential exploitation attempts.
  • Restrict access to critical endpoints and employ firewalls or intrusion detection/prevention systems to mitigate unauthorized access.
  • Conduct thorough security audits periodically to detect and rectify any existing weaknesses or unauthorized modifications.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2026-6875 Scanner - Remote Code Execution (RCE) vulnerability in ServiceNow AI Platform S4E