ZeroHour

CVE-2026-18886

large

Improper Access Control (Privilege Escalation) in ServiceNow AI Platform

CVSS 4.0
10.0 critical
EPSS
<1%p16
Published
()
Modified
AI analysis

CVE-2026-18886 is an improper access control vulnerability (CWE-284) in the ServiceNow AI Platform that, in certain circumstances, allows an unauthenticated remote user to create or modify instance data beyond what was intended. Because the flaw is reachable over the network with no privileges or user interaction required, an attacker who meets the advisory's conditions can manipulate instance data and achieve privilege escalation. Successful exploitation carries high impact to the confidentiality, integrity, and availability of the affected instance (CVSS 4.0 score of 10.0). Customers running affected ServiceNow AI Platform releases are potentially affected; ServiceNow has already deployed the security update to hosted instances, while self-hosted customers and partners must apply the provided update themselves. No exploitation has been observed to date (EPSS 0.2%, not listed in CISA KEV, no public proof-of-concept).

What to do: Self-hosted customers and partners should promptly apply the ServiceNow-provided security update or upgrade to a patched release, and hosted-instance administrators should verify their instance is running the patched build. Given the unauthenticated network vector and CVSS 4.0 score of 10.0, prioritize this patch even though no exploitation or public PoC is known. Monitor ServiceNow's advisory for updated guidance and indicators.

Affected
ServiceNow AI Platform
Estimated exposure
large≈ tens of thousands of instances across ServiceNow's enterprise customer base (hosted instances auto-patched; residual unpatched exposure concentrated in… — ServiceNow serves thousands of enterprise customers that typically run multiple instances, implying an install base in the tens of thousands, though the currently exposed population is smaller because hosted instances were patched by…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

ServiceNow has remediated an improper access control vulnerability that was identified in the ServiceNow AI platform. This vulnerability could enable an unauthenticated user, in certain circumstances, to create or modify instance data beyond what was intended, resulting in privilege escalation. ServiceNow deployed a security update to hosted instances and ServiceNow provided the update to our partners and self-hosted customers. We are not currently aware of exploitation against ServiceNow instances. We recommend customers promptly apply appropriate updates or upgrade to a patched release if they have not already done so.

Weakness
CWE-284
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

Three CVSS 10.0 ServiceNow Flaws Could Let Unauthenticated Attackers Execute Code and SQL

ServiceNow patched four AI Platform flaws, including three pre-authentication CVSS 10.0 issues enabling unauthenticated code execution, SQL injection, and privilege escalation.

ServiceNow released patches on August 27, 2026 for four AI Platform flaws: CVE-2026-18885 (code injection in the GraphQL Composite Data API), CVE-2026-18886 (improper access control enabling privilege escalation), and CVE-2026-74820 (SQL injection), all self-rated CVSS 10.0 and exploitable without authentication, plus CVE-2026-6876, an 8.7 sandbox escape. Updates were deployed to hosted instances, but self-hosted customers must patch affected Xanadu, Yokohama, Zurich, and Australia release lines themselves. ServiceNow says it is not aware of exploitation of the new flaws, and no public exploit code existed as of August 28, 2026; separately, Defused reported in-the-wild exploitation of the earlier CVE-2026-6875 (CVSS 9.5), later noting the captured payload matched Searchlight Cyber's PoC.

The Hacker News · 18d agoVulnerability in the wildCVE-2026-18885CVE-2026-18886CVE-2026-74820+2 CVEs