AI analysis
CVE-2026-74820 is a critical (CVSS 4.0: 10.0) SQL injection flaw (CWE-89) in the ServiceNow AI platform that an unauthenticated attacker can, in certain circumstances, trigger remotely over the network. Successful exploitation allows arbitrary SQL statements to be executed against the instance's underlying database, giving the attacker access to or the ability to modify instance data beyond what was intended, with the CVSS scoring indicating high impact to confidentiality, integrity, and availability. Any organization running an unpatched ServiceNow instance is affected, but ServiceNow has already deployed the security update to its hosted instances, so remaining exposure is concentrated among self-hosted customers and partners who must apply the provided update themselves. There is currently no known malicious exploitation: EPSS assigns a 0.2% probability of exploitation within 30 days, the flaw is not in CISA KEV, and no public proof-of-concept is known.
What to do: Self-hosted customers and partners should promptly apply the ServiceNow security update or upgrade to a patched release, and verify that any hosted instances received the automatic update. Review ServiceNow's related advisories covering the reported set of three CVSS 10.0 ServiceNow flaws (unauthenticated code execution and SQL injection) and apply the full patch bundle. Since no in-the-wild exploitation is known, patch urgently per vendor guidance and confirm instances are no longer running unpatched releases.
Estimated exposure
mass≈ millions of enterprise users across thousands of customer instances (ServiceNow serves thousands of enterprise customers, including a majority of the Fortune… — Based on ServiceNow's deployment patterns and market share as a leading enterprise workflow/ITSM SaaS platform with thousands of large enterprise customers and tens of thousands of cloud and self-hosted instances, the plausible affected…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
ServiceNow has remediated a SQL injection vulnerability that was identified in in the ServiceNow AI platform. This vulnerability could enable an unauthenticated user, in certain circumstances, to execute arbitrary SQL statements against the instance's underlying database and gain access to, or modify, instance data beyond what was intended. ServiceNow deployed a security update to hosted instances and ServiceNow provided the update to our partners and self-hosted customers. We are not currently aware of malicious exploitation against ServiceNow instances. We recommend customers promptly apply appropriate updates or upgrade to a patched release if they have not already done so.