Back

CRITICAL

Sandbox Escape in ServiceNow AI Platform

Published Aug 27, 2026

Description

ServiceNow has remediated a sandbox escape security issue that was identified in the ServiceNow AI Platform. This security issue could allow an unauthenticated user to execute arbitrary code within the ServiceNow AI Platform, potentially leading to more access to the ServiceNow AI Platform than intended. 

ServiceNow deployed a security update to hosted instances and ServiceNow provided the update to our partners and self-hosted customers. We are not currently aware of malicious exploitation against ServiceNow instances. 

We recommend customers promptly apply appropriate updates or upgrade to a patched release if they have not already done so.

Affected products

Remediation

No remediation recorded yet.

References (2)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner SN
Published Aug 27, 2026
Updated Sep 1, 2026
Reserved Apr 22, 2026
CISA Vulnrichment
Updated Aug 28, 2026
NVD
Status Awaiting Analysis
Modified Sep 1, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner SN
Published Aug 27, 2026
Updated Sep 1, 2026
Exploited since n/a
EUVD-2026-67218