ServiceNow CVE-2024-5178
ServiceNow Remote Code Execution
Risk & exploitation
EPSS (FIRST) estimates a low-to-moderate likelihood of exploitation in the next 30 days (2026-06-10). Priority blends CVSS, EPSS, KEV and public-exploit availability — operational prioritization, not a NIS2/DORA reporting determination.
Summary
ServiceNow has addressed a sensitive file read vulnerability that was identified in the Washington DC, Vancouver, and Utah Now Platform releases. This vulnerability could allow an administrative user to gain unauthorized access to sensitive files on the web application server. The vulnerability is addressed in the listed patches and hot fixes, which were released during the June 2024 patching cycle. If you have not done so already, we recommend applying security patches relevant to your instance as soon as possible.
Auto-generated stub from NVD. Detection signals and per-release fixed-in are pending manual authoring/verification; until a signal carries a verified match, the exposure check returns DORMANT/INVESTIGATE — never a false EXERCISED.Affected releases & fixed-in
| Release | Fixed in |
|---|---|
| Washington DC | Patch 1 Hot Fix 3b / Patch 2 Hot Fix 2 / Patch 3 Hot Fix 2 / Patch 4 |
| Vancouver | Patch 6 Hot Fix 2 / Patch 7 Hot Fix 3b / Patch 8 Hot Fix 4 / Patch 9 Hot Fix 1 / Patch 10 |
| Utah | Patch 10b Hot Fix 1 / Patch 10a Hot Fix 2 / Patch 10 Hot Fix 3 |
Source & attribution
Per-release fixed-in VERIFIED against the ServiceNow-authored CVE Record (CNA shortName: SN) — affected[].versions[] boundaries, https://cveawg.mitre.org/api/cve/CVE-2024-5178 (retrieved 2026-06-08). The same patch matrix is in the login-gated ServiceNow KB; the public CVE Record is the citable source.
Regulatory mapping
- NIS2 Art.21§2(a)
- NIS2 Art.21§2(d)
- NIS2 Art.21§2(e)
- NIS2 Art.23§1
- DORA Art.9§1
- DORA Art.9§2
- DORA Art.17§1
- DORA RTS Art.10
- DORA RTS Art.11
- DORA RTS Art.22
- ISO A.8.8
- ISO A.8.9
- ISO A.8.28
Decision support, not a reporting determination.
References
Data: GitHub Advisory Database (CC-BY 4.0), NVD, the CISA KEV catalog, FIRST EPSS, Exploit-DB, and Nuclei templates.