Executive brief
ServiceNow AI Platform is a cloud service that processes and executes AI workflows. An unauthenticated attacker could escape the sandbox environment and execute arbitrary code, gaining unauthorized access to the platform and potentially compromising data or operations within ServiceNow instances.
Technical details
This vulnerability is a sandbox escape flaw in the ServiceNow AI Platform that permits unauthenticated remote code execution. The attack requires no authentication or user interaction and is network-accessible. An attacker can break out of the sandbox containment and execute arbitrary code within the AI Platform, potentially gaining access to broader ServiceNow instance resources. ServiceNow has deployed security updates to hosted instances and provided patches to partners and self-hosted customers; no active exploitation has been reported.
Affected products
- ServiceNow AI Platform
Timeline
- 2026-08-27: disclosed
- patched: Security update deployed to hosted instances; patch provided to partners and self-hosted customers