CVE-2026-6875
Awaiting Analysis Awaiting Analysis - Queue

Remote Code Execution in ServiceNow AI Platform

Vulnerability report for CVE-2026-6875, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-13

Last updated on: 2026-07-14

Assigner: ServiceNow

Description

ServiceNow has addressed a remote code execution vulnerability that was identified in the ServiceNow AI platform. This vulnerability could enable an unauthenticated user, in certain circumstances, to execute code within the ServiceNow platform. ServiceNow addressed this vulnerability by deploying a security update to hosted instances. Relevant security updates have also been provided to ServiceNow self-hosted customers and partners. Further, the vulnerability is addressed in the listed patches and family releases, which have been made available to hosted and self-hosted customers, as well as partners. We are not currently aware of exploitation against ServiceNow instances. We recommend customers promptly apply appropriate updates or upgrade to a patched release if they have not already done so.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-13
Last Modified
2026-07-14
Generated
2026-08-03
AI Q&A
2026-07-14
EPSS Evaluated
2026-08-01
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
servicenow ai_platform *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-94 The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-6875 is a remote code execution vulnerability identified in the ServiceNow AI platform. It allows an unauthenticated user, under certain circumstances, to execute arbitrary code within the ServiceNow platform. This means an attacker could potentially run malicious code on a vulnerable ServiceNow instance without needing any credentials.

ServiceNow has addressed this vulnerability by deploying security updates to their hosted instances and providing relevant patches to self-hosted customers and partners. The issue is resolved in specific patches and family releases, which are available for both hosted and self-hosted environments.

Detection Guidance

The provided context does not include specific detection methods or commands for identifying the presence of CVE-2026-6875 on a network or system. Detection typically involves checking the ServiceNow instance version or patch level to determine if it is vulnerable.

ServiceNow recommends verifying whether the appropriate security updates or patched releases have been applied. Customers should review the ServiceNow instance for the presence of the patches listed in KB3137947 or confirm their instance is running a fixed version.

  • Check the ServiceNow instance version or patch level via the ServiceNow admin console or support portal.
  • Review the KB3137947 article on the ServiceNow Support Portal for specific patch details and verification steps.
Impact Analysis

If you are using a vulnerable version of the ServiceNow AI platform, this vulnerability could have severe impacts, including:

  • Unauthorized access to sensitive data stored or processed within the ServiceNow platform.
  • Execution of malicious code, which could lead to data breaches, system compromise, or further exploitation of connected systems.
  • Disruption of business operations if the attacker manipulates or deletes critical data or services.

Since the vulnerability can be exploited by an unauthenticated user, the risk is heightened, especially if the ServiceNow instance is exposed to the internet.

Compliance Impact

This vulnerability could significantly impact compliance with various standards and regulations, depending on the data and systems involved:

  • GDPR: If the ServiceNow platform processes or stores personal data of EU citizens, a successful exploit could lead to unauthorized access or disclosure of this data. This would violate GDPR requirements for data protection and could result in hefty fines and legal consequences.
  • HIPAA: For organizations handling protected health information (PHI), exploitation of this vulnerability could lead to unauthorized access to PHI, violating HIPAA's security and privacy rules. This could result in penalties and mandatory corrective actions.
  • Other standards: Compliance with frameworks like ISO 27001, SOC 2, or PCI DSS may also be affected if the vulnerability leads to a breach of confidentiality, integrity, or availability of sensitive information or systems.

Organizations should promptly apply the provided patches to mitigate these risks and maintain compliance with applicable regulations.

Mitigation Strategies

To mitigate CVE-2026-6875, ServiceNow recommends the following immediate steps:

  • Apply the relevant security updates or patches provided by ServiceNow to hosted instances.
  • For self-hosted customers and partners, upgrade to a patched release as specified in the security advisory.
  • Refer to KB3137947 on the ServiceNow Support Portal for detailed instructions on applying the updates.
  • If immediate patching is not possible, consider temporarily restricting access to the ServiceNow AI platform until the updates are applied.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-6875. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart