← Vulnerability feed

Vulnerability record · CVE-2024-5217 · published 10 July 2024

CVE-2024-5217: ServiceNow Now Platform input validation flaw enables unauthenticated RCE

Servicenow · Servicenow

ServiceNow's Washington DC, Vancouver, and earlier Now Platform releases contain an input validation vulnerability (CWE-184 incomplete list of disallowed inputs, CWE-697 incorrect comparison) that allows an unauthenticated remote attacker to execute code in the context of the Now Platform. It is remotely reachable, requires no credentials or user interaction, and affects core platform instances, making it a high-value target for initial access.

9.2 CVSS 4.0 Critical CISA KEV since 29 Jul 2024 EPSS 100% · top 0.1% CWE-184 · CWE-184CWE-697 · CWE-697
9.2CVSS 4.0 base score
100%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
7References
17 Jun 2026Last modified by NVD

Description

ServiceNow has addressed an input validation vulnerability that was identified in the Washington DC, Vancouver, and earlier Now Platform releases. This vulnerability could enable an unauthenticated user to remotely execute code within the context of the Now Platform. The vulnerability is addressed in the listed patches and hot fixes below, which were released during the June 2024 patching cycle. If you have not done so already, we recommend applying security patches relevant to your instance as soon as possible.

CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 16 September 2026. Confidence: high.

critical priorityUnauthenticated network-reachable RCE with CVSS 9.2, active exploitation per CISA KEV, and an EPSS probability above 99%.

What it is

ServiceNow's Washington DC, Vancouver, and earlier Now Platform releases contain an input validation vulnerability (CWE-184 incomplete list of disallowed inputs, CWE-697 incorrect comparison) that allows an unauthenticated remote attacker to execute code in the context of the Now Platform. It is remotely reachable, requires no credentials or user interaction, and affects core platform instances, making it a high-value target for initial access.

Impact

An attacker gains remote code execution within the Now Platform, which can lead to full compromise of the instance and any data or integrations it holds. Because the platform often stores sensitive workflow, ticket, and identity data, the blast radius extends beyond the server itself.

Attack surface

Reached over the network via the Now Platform interface (CVSS 4.0 vector AV:N/PR:N/UI:N), so no authentication and no user interaction are required. The only noted precondition is AT:P (attack requirements present), meaning some specific target configuration or condition must exist for exploitation.

Exploitation

CISA added it to the Known Exploited Vulnerabilities catalog on 2024-07-29 with a remediation due date of 2024-08-19, and EPSS shows a 30-day probability of 0.99628 (99.9th percentile), indicating active exploitation in the wild. Press coverage also describes active exploitation of the ServiceNow RCE bugs.

What to do

  • Apply the ServiceNow patches and hot fixes released in the June 2024 patching cycle for Washington DC, Vancouver, and earlier Now Platform releases.
  • If patching cannot be completed immediately, follow ServiceNow's vendor guidance in KB1644293 and KB1648313 and consider restricting or disabling the affected functionality.
  • Limit network exposure of Now Platform instances to trusted networks and users where operationally feasible.
  • Monitor for and block exploitation attempts at the edge (WAF/IDS) using vendor and CISA guidance.
  • Verify patch level of all Now Platform instances, including non-production and internet-facing ones, and track completion against the CISA due date.

Detection

  • Review Now Platform and web server logs for anomalous requests or unexpected code execution patterns around the affected input handling.
  • Hunt for unusual child processes, script execution, or outbound connections originating from the Now Platform service account.
  • Correlate network and application logs for unauthenticated requests that reach code paths tied to the vulnerable input validation.
  • Check for indicators published by ServiceNow and CISA related to this CVE and alert on matches.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2024-5217 to the Known Exploited Vulnerabilities catalog on 29 July 2024 as "ServiceNow Incomplete List of Disallowed Inputs Vulnerability". Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 19 August 2024.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-5217 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.3CVE-2024-4879ServiceNow Now Platform input validation flaw allows unauthenticated RCEServiceNow's Now Platform (Vancouver and Washington DC releases) contains an input validation vulnerability that lets an unauthenticated remote attac…KEVEPSS 100%analysed9.3CVE-2024-8923Servicenow code injection vulnerabilityServiceNow has addressed an input validation vulnerability that was identified in the Now Platform. This vulnerability could enable an unauthenticate…EPSS 1.1%8.8CVE-2018-7748Servicenow code injection vulnerabilityreport_viewer.do in ServiceNow Release Jakarta Patch 8 and earlier allows remote attackers to execute arbitrary code via '${xyz}' Glide Scripting Inj…EPSS 2.6%8.7CVE-2024-8924Servicenow sql injection vulnerabilityServiceNow has addressed a blind SQL injection vulnerability that was identified in the Now Platform. This vulnerability could enable an unauthentica…EPSS 0.50%6.5CVE-2022-43684Servicenow information exposure vulnerabilityServiceNow has released patches and an upgrade that address an Access Control List (ACL) bypass issue in ServiceNow Core functionality. Additional De…EPSS 1.8%6.1CVE-2023-1298Servicenow cross-site scripting vulnerabilityServiceNow has released upgrades and patches that address a Reflected Cross-Site scripting (XSS) vulnerability that was identified in the ServiceNow …EPSS 0.39%6.1CVE-2022-46389Servicenow cross-site scripting vulnerabilityThere exists a reflected XSS within the logout functionality of ServiceNow versions lower than Quebec Patch 10 Hotfix 11b, Rome Patch 10 Hotfix 3b, S…EPSS 0.60%6.1CVE-2022-46886Servicenow open redirect vulnerabilityThere exists an open redirect within the response list update functionality of ServiceNow. This allows attackers to redirect users to arbitrary domai…EPSS 0.30%

Source: NIST National Vulnerability Database (record CVE-2024-5217), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.