ZeroHour

CVE-2026-18885

mass

Unauthenticated Code Injection in ServiceNow AI Platform (CVSS 10.0)

CVSS 4.0
10.0 critical
EPSS
<1%p36
Published
()
Modified
AI analysis

ServiceNow has remediated an unauthenticated code injection vulnerability (CWE-94) in the ServiceNow AI platform, scored a maximum 10.0 in CVSS 4.0, exploitable over the network with no privileges and no user interaction. An attacker can trigger it, in certain circumstances, via crafted input to an affected instance, gaining the ability to execute arbitrary code on the platform and access or modify instance data beyond intended permission boundaries. All customers running the affected platform are in scope: ServiceNow has already deployed the fix to hosted instances, while partners and self-hosted customers must apply the provided update or upgrade to a patched release. Related reporting indicates this is one of three CVSS 10.0 ServiceNow flaws disclosed together that could allow unauthenticated code and SQL execution, though specific affected version ranges are not listed in the advisory. There is no public proof-of-concept, the flaw is not in CISA's KEV, EPSS is low (0.4% in 30 days), and ServiceNow states it is not currently aware of malicious exploitation.

What to do: Self-hosted and partner-hosted customers should promptly apply the ServiceNow-provided security update or upgrade to a patched release; hosted instances have already been updated by ServiceNow, so confirm your deployment model and current patch level against ServiceNow's advisory. Because the flaw is network-exploitable without authentication, prioritize any internet-exposed instances and review for signs of unexpected code execution or unauthorized data access. No workarounds are stated in the advisory; monitor ServiceNow PSIRT for updates, noting related coverage of three CVSS 10.0 flaws in this set.

Affected
ServiceNow AI platform
Estimated exposure
masstens of thousands of internet-exposed ServiceNow instances (order 10^4) serving millions of users in aggregate — ServiceNow's enterprise customer base (thousands of organizations with heavy Fortune 500 adoption) and public internet scans that have repeatedly shown on the order of tens of thousands of internet-facing ServiceNow instances imply…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

ServiceNow has remediated a code injection vulnerability that was identified in the ServiceNow AI platform. This vulnerability could enable an unauthenticated user, in certain circumstances, to execute arbitrary code in the ServiceNow platform and gain access to, or modify, instance data beyond what was intended. ServiceNow deployed a security update to hosted instances and ServiceNow provided the update to our partners and self-hosted customers. We are not currently aware of malicious exploitation against ServiceNow instances. We recommend customers promptly apply appropriate updates or upgrade to a patched release if they have not already done so.

Weakness
CWE-94
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

Three CVSS 10.0 ServiceNow Flaws Could Let Unauthenticated Attackers Execute Code and SQL

ServiceNow patched four AI Platform flaws, including three pre-authentication CVSS 10.0 issues enabling unauthenticated code execution, SQL injection, and privilege escalation.

ServiceNow released patches on August 27, 2026 for four AI Platform flaws: CVE-2026-18885 (code injection in the GraphQL Composite Data API), CVE-2026-18886 (improper access control enabling privilege escalation), and CVE-2026-74820 (SQL injection), all self-rated CVSS 10.0 and exploitable without authentication, plus CVE-2026-6876, an 8.7 sandbox escape. Updates were deployed to hosted instances, but self-hosted customers must patch affected Xanadu, Yokohama, Zurich, and Australia release lines themselves. ServiceNow says it is not aware of exploitation of the new flaws, and no public exploit code existed as of August 28, 2026; separately, Defused reported in-the-wild exploitation of the earlier CVE-2026-6875 (CVSS 9.5), later noting the captured payload matched Searchlight Cyber's PoC.

The Hacker News · 18d agoVulnerability in the wildCVE-2026-18885CVE-2026-18886CVE-2026-74820+2 CVEs