Preliminary research
Smashing the ServiceNow Sandbox – Pre-Authentication RCE
Smashing the ServiceNow Sandbox – Pre Authentication RCE
AI-collected research leads through 22 September 2026, including targeted additions between broader sweeps. Unranked, incomplete, not community-vetted, and subject to change.
An unauthenticated remote code execution flaw in ServiceNow (CVE-2026-6875). User input reaching GlideRecord query builders is evaluated as JavaScript when prefixed with javascript:, and although such expressions run under a restrictive script sandbox, the script-include mechanism evaluates library code outside it. Redefining the global helpers those libraries call turns an include into a Function constructor invocation, escaping the sandbox and yielding full instance and proxy-server access.
Record
- Document
- Smashing the ServiceNow Sandbox – Pre Authentication RCE
- Researcher
- Adam Kues and @searchlightsec
- Published by
- Searchlight Cyber
- Date
- Topic
- Identity
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Adam Kues and @searchlightsec, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .