← Vulnerability feed

Vulnerability record · CVE-2024-4879 · published 10 July 2024

CVE-2024-4879: ServiceNow Now Platform input validation flaw allows unauthenticated RCE

Servicenow · Servicenow

ServiceNow's Now Platform (Vancouver and Washington DC releases) contains an input validation vulnerability that lets an unauthenticated remote attacker execute code in the platform's context. Because the platform is widely used for IT service management and often internet-facing, successful exploitation gives a foothold inside enterprise environments. ServiceNow has patched hosted instances and released updates for self-hosted customers.

9.3 CVSS 4.0 Critical CISA KEV since 29 Jul 2024 EPSS 100% · top 0.1% CWE-1287 · CWE-1287
9.3CVSS 4.0 base score
100%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
7References
17 Jun 2026Last modified by NVD

Description

ServiceNow has addressed an input validation vulnerability that was identified in Vancouver and Washington DC Now Platform releases. This vulnerability could enable an unauthenticated user to remotely execute code within the context of the Now Platform. ServiceNow applied an update to hosted instances, and ServiceNow released the update to our partners and self-hosted customers. Listed below are the patches and hot fixes that address the vulnerability. If you have not done so already, we recommend applying security patches relevant to your instance as soon as possible.

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 16 September 2026. Confidence: high.

critical priorityUnauthenticated remote code execution with a CVSS 4.0 score of 9.3, CISA KEV listing, and near-maximum EPSS probability make this an urgent patch-first issue.

What it is

ServiceNow's Now Platform (Vancouver and Washington DC releases) contains an input validation vulnerability that lets an unauthenticated remote attacker execute code in the platform's context. Because the platform is widely used for IT service management and often internet-facing, successful exploitation gives a foothold inside enterprise environments. ServiceNow has patched hosted instances and released updates for self-hosted customers.

Impact

An unauthenticated attacker can run arbitrary code with the privileges of the Now Platform, potentially leading to full compromise of the instance and access to connected enterprise data and systems.

Attack surface

Reachable over the network with no authentication and no user interaction required, per the CVSS 4.0 vector (AV:N/PR:N/UI:N). Any internet-exposed or internally reachable Now Platform instance running an affected release is a candidate target.

Exploitation

CISA added this to the Known Exploited Vulnerabilities catalog on 2024-07-29 with a due date of 2024-08-19, and press coverage describes active exploitation; EPSS is 0.99976 (99.978th percentile). No ransomware campaign use is documented in the record.

What to do

  • Apply the ServiceNow patches and hot fixes for the Vancouver and Washington DC releases immediately; hosted instances were already updated by ServiceNow.
  • If patching cannot be completed at once, follow ServiceNow's vendor guidance and consider restricting or discontinuing external exposure of the instance.
  • Limit network access to the Now Platform to trusted sources and remove any unnecessary internet-facing exposure.
  • Verify the instance version against ServiceNow's advisory to confirm whether it is affected.
  • Monitor for signs of compromise on instances that were exposed before patching.

Detection

  • Review Now Platform logs for anomalous or unexpected requests and errors consistent with input validation bypass attempts.
  • Hunt for unexpected processes, scripts, or outbound connections originating from the Now Platform host.
  • Check for unauthorized changes to platform configuration, users, or records that could indicate post-exploitation activity.
  • Correlate network logs for scanning or exploitation attempts against Now Platform endpoints.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2024-4879 to the Known Exploited Vulnerabilities catalog on 29 July 2024 as "ServiceNow Improper Input Validation Vulnerability". Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 19 August 2024.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-4879 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.2CVE-2024-5217ServiceNow Now Platform input validation flaw enables unauthenticated RCEServiceNow's Washington DC, Vancouver, and earlier Now Platform releases contain an input validation vulnerability (CWE-184 incomplete list of disall…KEVEPSS 100%analysed9.3CVE-2024-8923Servicenow code injection vulnerabilityServiceNow has addressed an input validation vulnerability that was identified in the Now Platform. This vulnerability could enable an unauthenticate…EPSS 1.1%8.8CVE-2018-7748Servicenow code injection vulnerabilityreport_viewer.do in ServiceNow Release Jakarta Patch 8 and earlier allows remote attackers to execute arbitrary code via '${xyz}' Glide Scripting Inj…EPSS 2.6%8.7CVE-2024-8924Servicenow sql injection vulnerabilityServiceNow has addressed a blind SQL injection vulnerability that was identified in the Now Platform. This vulnerability could enable an unauthentica…EPSS 0.50%6.5CVE-2022-43684Servicenow information exposure vulnerabilityServiceNow has released patches and an upgrade that address an Access Control List (ACL) bypass issue in ServiceNow Core functionality. Additional De…EPSS 1.8%6.1CVE-2023-1298Servicenow cross-site scripting vulnerabilityServiceNow has released upgrades and patches that address a Reflected Cross-Site scripting (XSS) vulnerability that was identified in the ServiceNow …EPSS 0.39%6.1CVE-2022-46389Servicenow cross-site scripting vulnerabilityThere exists a reflected XSS within the logout functionality of ServiceNow versions lower than Quebec Patch 10 Hotfix 11b, Rome Patch 10 Hotfix 3b, S…EPSS 0.60%6.1CVE-2022-46886Servicenow open redirect vulnerabilityThere exists an open redirect within the response list update functionality of ServiceNow. This allows attackers to redirect users to arbitrary domai…EPSS 0.30%

Source: NIST National Vulnerability Database (record CVE-2024-4879), CISA KEV, FIRST EPSS (scores of 2026-09-21). This page is refreshed as NVD updates the record.