Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2026-6875-PoC-Exploit — CVE-2026-6875 ServiceNow Pre-Auth RCE Framework 🔥 JS Injection → Sandbox Escape → RCE → Root. Features: --detect, --exec, reverse/interactive shell, batch threading, WAF bypass, persistence, lateral movement, credential dump, fileless exec, clean tracks. 🛡️ CVSS 9.5 actively exploited. Authorized & Legal use only. Stay Legal. 🔒 | Kitploit
Tools/GitHubGitHub/tc4dy/cve-2026-6875-poc-exploit
Privilege EscalationVulnerability ScannersPersistence MechanismsExploitationLateral MovementWeb Application ExploitationPost-ExploitationWAF BypassPenetration Testing

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →

About

CVE-2026-6875 ServiceNow Pre-Auth RCE Framework 🔥 JS Injection → Sandbox Escape → RCE → Root. Features: --detect, --exec, reverse/interactive shell, batch threading, WAF bypass, persistence, lateral movement, credential dump, fileless exec, clean tracks. 🛡️ CVSS 9.5 actively exploited. Authorized & Legal use only. Stay Legal. 🔒

Remote Access Tool
GitHubtc4dy/cve-2026-6875-poc-exploit

CVE-2026-6875-PoC-Exploit

View Repository
3252 months agoNot yet reviewed
Share

CVE-2026-6875

CVE-2026-6875 - ServiceNow Pre‑Auth RCE Exploit Framework & PoC Verifier 🔥

CVE-2026-6875 CVSS 9.5 CISA KEV Python 3.6+

Pre-Auth RCE Sandbox Escape Privesc Windows Ready

ServiceNow AI Platform — JavaScript Injection → Sandbox Escape → RCE → Root Privesc

Exploit Framework & Safe Verifier
For authorized security testing only.


⚖️ Legal Disclaimer & Responsible Use

This tool is provided for educational and authorized penetration testing purposes only.

The authors and contributors are not responsible for any misuse or damage caused by this software. Users are solely responsible for ensuring they have explicit written permission from the target owner before testing. Unauthorized access to computer systems is illegal under the Computer Fraud and Abuse Act (CFAA) and similar laws worldwide.

By using this software, you agree to:

  • Use it only on systems you own or have explicit permission to test.
  • Comply with all applicable local, state, and federal laws.
  • Not use it for any malicious, destructive, or illegal activities.

⚠️ WARNING: This vulnerability is actively exploited in the wild. Unauthorized use may result in severe legal consequences.


🔥 Vulnerability Overview

CVE-2026-6875 is a critical unauthenticated Remote Code Execution (RCE) vulnerability in the ServiceNow AI Platform (formerly Now Platform). It allows attackers to bypass the script sandbox and execute arbitrary system commands with the privileges of the ServiceNow application.

How it works:

  1. JavaScript Injection: The assessment_thanks.do endpoint accepts a sysparm_assessable_type parameter. By prefixing the value with javascript:, an attacker injects arbitrary JavaScript code.

  2. Sandbox Escape: A sophisticated sandbox‑escape gadget (chaining DiscoveryFunctions.getCacheObjectForTable, AbstractAjaxProcessor, and Class.create) lifts the JavaScript sandbox restriction.

  3. Remote Code Execution: The injected Java code (via java.lang.Runtime.exec()) runs with ServiceNow application privileges, enabling full system compromise.

  4. Privilege Escalation: Post‑exploitation modules attempt to escalate to root via sudo misconfigurations, SUID binaries, writable cron jobs, or kernel exploits.

Key Facts:

AttributeValue
📅 DiscoveredApril 1, 2026 (Searchlight Cyber)
⚠️ CVSS Score9.5 (CRITICAL)
📋 CISA KEVAdded July 13, 2026
🎯 Affected ProductsSelf‑hosted ServiceNow AI Platform
🔄 Fixed VersionsBrazil EA/GA, Australia Patch 2, Zurich Patch 7b/9, Yokohama Patch 12 Hot Fix 1b/13
🔓 AuthenticationNot required (Pre‑Auth)
🌍 Active ExploitationConfirmed in the wild (July 2026)

🛠️ Exploit Framework (exploit.py)

The full weaponized exploit chains the JavaScript injection and sandbox escape to achieve remote code execution, with advanced post‑exploitation modules for persistence, lateral movement, and credential dumping.

✨ Features

FeatureDescription
🚀 JavaScript InjectionInjects payload via sysparm_assessable_type parameter.
💻 Sandbox EscapeBypasses ServiceNow's script sandbox to run arbitrary Java code.
🔐 Interactive ShellSpawn a live shell with support for multiple commands.
👑 Root PrivescChecks for sudo misconfigurations, SUID binaries, and cron jobs.
📁 File OperationsUpload webshells, read/download files via base64 encoding.
🌐 Batch ScanningMass exploit multiple targets with threading (-l flag).
🎯 Safe DetectionOptional --detect flag for non‑intrusive vulnerability verification.
⚙️ WAF BypassBuilt‑in obfuscation techniques to evade WAF/IDS (6 techniques).
🧩 PersistenceInstalls cron/systemd/schtasks backdoors.
🔍 Lateral MovementScans local network for other vulnerable hosts and attempts SSH/SSRF propagation.
🧹 Clean TracksRemoves logs, bash history, and audit trails.
💾 Fileless ExecutionUses Java ClassLoader to run memory‑resident payloads without writing to disk.
🔌 Callback ServerBuilt‑in HTTP server to receive command output (optional).
📢 Webhook NotificationsSends results to a custom URL (Slack, Discord, etc.).
🪟 Cross‑PlatformSupports Linux and Windows targets (cmd.exe / PowerShell).
🔒 Thread‑SafeUses locking mechanisms for concurrent operations.
📊 Version DetectionDetects ServiceNow version (Zurich/Brazil/Australia/Yokohama).

Interactive Shell Commands

CommandDescription
exec <cmd>Execute system command
upload <local> [remote]Upload webshell to target
download <remote>Download and display file content
privescAttempt privilege escalation
reverse <host> <port>Send reverse shell
dumpcredDump credentials from ServiceNow configs
persist <host> <port>Install persistence (cron/systemd/schtasks)
lateralAttempt lateral movement
cleanClean tracks (logs, history)
memory <host> <port>Execute fileless Java payload
exitExit interactive shell

🕵️ Safe Verifier (verifier.py)

The safe verifier performs non‑intrusive vulnerability detection without executing harmful payloads or making system changes.

✨ Features

FeatureDescription
🔍 ServiceNow DetectionIdentifies ServiceNow instances via multiple endpoints.
📊 Version DetectionDetects specific ServiceNow releases and patch levels.
🧪 JavaScript Injection TestTests for injection vulnerability using safe gs.print() payloads.
🔒 Sandbox Escape TestVerifies sandbox escape without destructive commands.
📈 Confidence ScoringProvides confidence percentage (85‑95%) based on evidence.
📋 JSON OutputExport results to JSON format for reporting.
🔄 Mass ScanningScan multiple targets with threading support.
🎯 Non‑IntrusiveOnly executes benign uname -a for system info.

📦 Installation & Requirements

Prerequisites

  • Python 3.6+
  • pip (for requests library)

Install Dependencies

pip install requests urllib3

[!NOTE] exploit.py uses only the standard library for core functionality; requests is only required for the --detect feature, --webhook notifications, and safe verifier.


🚀 Usage Examples

[1] Safe Verifier (verifier.py)

Download Tool