Web Hack List

Preliminary research

Smashing the ServiceNow Sandbox – Pre-Authentication RCE

Smashing the ServiceNow Sandbox – Pre Authentication RCE

AI-collected research leads through 22 September 2026, including targeted additions between broader sweeps. Unranked, incomplete, not community-vetted, and subject to change.

An unauthenticated remote code execution flaw in ServiceNow (CVE-2026-6875). User input reaching GlideRecord query builders is evaluated as JavaScript when prefixed with javascript:, and although such expressions run under a restrictive script sandbox, the script-include mechanism evaluates library code outside it. Redefining the global helpers those libraries call turns an include into a Function constructor invocation, escaping the sandbox and yielding full instance and proxy-server access.

Record

Document
Smashing the ServiceNow Sandbox – Pre Authentication RCE
Researcher
Adam Kues and @searchlightsec
Published by
Searchlight Cyber
Date
Topic
Identity

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Adam Kues and @searchlightsec, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .