Sandbox Escape in ServiceNow AI Platform
Published Aug 27, 2026
10.0
CRITICALCVSS 4.0
EPSS 0.62%
Description
ServiceNow has remediated a sandbox escape security issue that was identified in the ServiceNow AI Platform. This security issue could allow an unauthenticated user to execute arbitrary code within the ServiceNow AI Platform, potentially leading to more access to the ServiceNow AI Platform than intended.
ServiceNow deployed a security update to hosted instances and ServiceNow provided the update to our partners and self-hosted customers. We are not currently aware of malicious exploitation against ServiceNow instances.
We recommend customers promptly apply appropriate updates or upgrade to a patched release if they have not already done so.
Affected products
-
- Version 0StatusaffectedConstraints<Australia Patch 2 Hot Fix 3
- Version 0StatusaffectedConstraints<Australia Patch 3 Hot Fix 2
- Version 0StatusaffectedConstraints<Australia Patch 3m
- Version 0StatusaffectedConstraints<Australia Patch 4
- Version 0StatusaffectedConstraints<Australia Patch 5
- Version 0StatusaffectedConstraints<Xanadu Patch 11 Hot Fix 7a
- Version 0StatusaffectedConstraints<Yokohama Patch 12 Hot Fix 3b
- Version 0StatusaffectedConstraints<Yokohama Patch 13 Hot Fix 4
- Version 0StatusaffectedConstraints<Zurich Patch 10 Hot Fix 2m (m-branch)
- Version 0StatusaffectedConstraints<Zurich Patch 10 Hot Fix 3 (standard)
- Version 0StatusaffectedConstraints<Zurich Patch 11
- Version 0StatusaffectedConstraints<Zurich Patch 12
- Version 0StatusaffectedConstraints<Zurich Patch 7b Hot Fix 3
- Version 0StatusaffectedConstraints<Zurich Patch 8 Hot Fix 5
- Version 0StatusaffectedConstraints<Zurich Patch 9 Hot Fix 6
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| ServiceNow | ServiceNow AI Platform | unaffected |
|
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (2)
Change history (0)
No recorded changes yet.