Web Hack List

Preliminary research

Smashing the ServiceNow Sandbox – Pre-Authentication RCE

AI-collected research leads through 6 October 2026, including bounded month-by-month reviews of selected social and community sources from January through September. Unranked, incomplete, not community-vetted, and subject to change.

An unauthenticated remote code execution flaw in ServiceNow (CVE-2026-6875). User input reaching GlideRecord query builders is evaluated as JavaScript when prefixed with javascript:, and although such expressions run under a restrictive script sandbox, the script-include mechanism evaluates library code outside it. Redefining the global helpers those libraries call turns an include into a Function constructor invocation, escaping the sandbox and yielding full instance and proxy-server access.

Record

Researcher
Adam Kues and @searchlightsec
Published by
Searchlight Cyber
Date

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Adam Kues and @searchlightsec, first published at the original source. Preserved copies are kept so the citation survives its host.