目標達成 すべての支援者に感謝 — 100%達成しました!

目標: 1000 CNY · 調達済み: 1336 CNY

100%

CVE-2026-6875— ServiceNow AI Platform 代码注入漏洞

AI Predicted 9.8 Difficulty: Moderate EPSS 24.49% · P98

Public Exploits 1

Possible ATT&CK Techniques 1AI

T1190 · Exploit Public-Facing Application

Affected Version Matrix 7

ベンダープロダクトVersion Rangeステータス
ServiceNowServiceNow AI Platform< Australia Patch 2affected
< Yokohama Patch 12 Hot Fix 1baffected
< Yokohama Patch 13affected
< Zurich Patch 7baffected
< Zurich Patch 9affected
< Brazil EAaffected
< Brazil GAaffected
新しい脆弱性情報の通知を購読するログインして購読

I. CVE-2026-6875の基本情報

脆弱性情報

脆弱性についてご質問がありますか?Shenlongの分析が参考になるかご確認ください!
Shenlongの10の質問を表示 ↗

高度な大規模言語モデル技術を使用していますが、出力には不正確または古い情報が含まれる可能性があります。Shenlongはデータの正確性を確保するよう努めていますが、実際の状況に基づいて検証・判断してください。

脆弱性タイトル
Sandbox Escape in ServiceNow AI Platform
ソース: CVE Program / CVE List V5
脆弱性説明
ServiceNow has addressed a remote code execution vulnerability that was identified in the ServiceNow AI platform. This vulnerability could enable an unauthenticated user, in certain circumstances, to execute code within the ServiceNow platform. ServiceNow addressed this vulnerability by deploying a security update to hosted instances. Relevant security updates have also been provided to ServiceNow self-hosted customers and partners. Further, the vulnerability is addressed in the listed patches and family releases, which have been made available to hosted and self-hosted customers, as well as partners. We are not currently aware of exploitation against ServiceNow instances. We recommend customers promptly apply appropriate updates or upgrade to a patched release if they have not already done so.
ソース: CVE Program / CVE List V5
CVSS情報
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
ソース: CVE Program / CVE List V5
脆弱性タイプ
N/A
ソース: CVE Program / CVE List V5
脆弱性タイトル
ServiceNow AI Platform 代码注入漏洞
ソース: CNNVD (China National Vulnerability Database)
脆弱性説明
ServiceNow AI Platform是美国ServiceNow公司的一款AI智能平台。 ServiceNow AI Platform存在代码注入漏洞,该漏洞源于代码注入问题,可能导致未经身份验证的用户在特定条件下在ServiceNow平台中执行代码。以下版本受到影响:Australia Patch 2之前版本、Yokohama Patch 12 Hot Fix 1b之前版本、Yokohama Patch 13之前版本、Zurich Patch 7b之前版本、Zurich Patch 9之前版本、B
ソース: CNNVD (China National Vulnerability Database)
CVSS情報
N/A
ソース: CNNVD (China National Vulnerability Database)
脆弱性タイプ
N/A
ソース: CNNVD (China National Vulnerability Database)

影響を受ける製品

ベンダープロダクト影響を受けるバージョンCPE購読
ServiceNowServiceNow AI Platform 0 ~ Australia Patch 2 -

II. CVE-2026-6875の公開POC

#POC説明ソースリンクShenlongリンク
1ServiceNow AI Platform (Brazil, Australia, Zurich, and Yokohama releases before patching) contains a pre-authentication remote code execution vulnerability. The /assessment_thanks.do endpoint passes the sysparm_assessable_type parameter into GlideRecord's addQuery(), which evaluates "javascript:" prefixed values as JavaScript in a restricted script sandbox. A sandbox escape gadget using Object.defineProperty and Class.create.constructor chains through the gs.include('ItemViewElementsProvider') path to invoke Function(code)(), bypassing the sandbox and executing arbitrary GlideController code. Actively exploited in the wild since July 2026. https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-6875.yamlPOC詳細
AI生成POCプレミアム
default-local-qwen3.6 · 8379 文字数
Pro+限定の内容:
脆弱性再現の録画(実際のサンドボックス構築 + トリガー、限定)
脆弱性の原理を深く分析
トリガー条件と影響範囲
完全な実行可能POCコード
攻撃チェーンと緩和策の提案
POCパッケージのダウンロード
月間100件以上のAI生成枠

III. CVE-2026-6875のインテリジェンス情報

登录查看更多情报信息。

CVE-2026-6875 厂商安全公告 (1)

IV. 関連脆弱性

V. CVE-2026-6875へのコメント

まだコメントはありません


コメントを残す