Three CVSS 10.0 ServiceNow Flaws Could Let Unauthenticated Attackers Execute Code and SQL
ServiceNow patched four AI Platform flaws, including three pre-authentication CVSS 10.0 issues enabling unauthenticated code execution, SQL injection, and privilege escalation.
ServiceNow released patches on August 27, 2026 for four AI Platform flaws: CVE-2026-18885 (code injection in the GraphQL Composite Data API), CVE-2026-18886 (improper access control enabling privilege escalation), and CVE-2026-74820 (SQL injection), all self-rated CVSS 10.0 and exploitable without authentication, plus CVE-2026-6876, an 8.7 sandbox escape. Updates were deployed to hosted instances, but self-hosted customers must patch affected Xanadu, Yokohama, Zurich, and Australia release lines themselves. ServiceNow says it is not aware of exploitation of the new flaws, and no public exploit code existed as of August 28, 2026; separately, Defused reported in-the-wild exploitation of the earlier CVE-2026-6875 (CVSS 9.5), later noting the captured payload matched Searchlight Cyber's PoC.
- Three flaws rated CVSS 10.0 need no privileges or user interaction, with high impact to confidentiality, integrity, and availability.
- Updates shipped to hosted instances; self-hosted customers must patch Xanadu, Yokohama, Zurich, and Australia release lines.
- Defused reported in-the-wild exploitation of CVE-2026-6875; the captured payload matched Searchlight Cyber's PoC.
- No public exploit code for the three 10.0 flaws as of August 28, 2026.
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-18885 | Unauthenticated Code Injection in ServiceNow AI Platform (CVSS 10.0) ServiceNow has remediated an unauthenticated code injection vulnerability (CWE-94) in the ServiceNow AI platform, scored a maximum 10.0 in CVSS 4.0, exploitable over the network with no privileges and no user interaction. An attacker can trigger it, in certain circumstances, via crafted input to an affected instance, gaining the ability to execute arbitrary code on the platform and access or modify instance data beyond intended permission boundaries. All customers running the affected platform are in scope: ServiceNow has already deployed the fix to hosted instances, while partners and self-hosted customers must apply the provided update or upgrade to a patched release. Related reporting indicates this is one of three CVSS 10.0 ServiceNow flaws disclosed together that could allow unauthenticated code and SQL execution, though specific affected version ranges are not listed in the advisory. There is no public proof-of-concept, the flaw is not in CISA's KEV, EPSS is low (0.4% in 30 days), and ServiceNow states it is not currently aware of malicious exploitation. Do: Self-hosted and partner-hosted customers should promptly apply the ServiceNow-provided security update or upgrade to a patched release; hosted instances have already been updated by ServiceNow, so confirm your deployment model and current patch level against ServiceNow's advisory. Because the flaw is network-exploitable without authentication, prioritize any internet-exposed instances and review for signs of unexpected code execution or unauthorized data access. No workarounds are stated in the advisory; monitor ServiceNow PSIRT for updates, noting related coverage of three CVSS 10.0 flaws in this set. | 10.0 | <1% |
| masstens of thousands of internet-exposed ServiceNow instances (order 10^4) serving millions of users in aggregate | ||
| CVE-2026-18886 | Improper Access Control (Privilege Escalation) in ServiceNow AI Platform CVE-2026-18886 is an improper access control vulnerability (CWE-284) in the ServiceNow AI Platform that, in certain circumstances, allows an unauthenticated remote user to create or modify instance data beyond what was intended. Because the flaw is reachable over the network with no privileges or user interaction required, an attacker who meets the advisory's conditions can manipulate instance data and achieve privilege escalation. Successful exploitation carries high impact to the confidentiality, integrity, and availability of the affected instance (CVSS 4.0 score of 10.0). Customers running affected ServiceNow AI Platform releases are potentially affected; ServiceNow has already deployed the security update to hosted instances, while self-hosted customers and partners must apply the provided update themselves. No exploitation has been observed to date (EPSS 0.2%, not listed in CISA KEV, no public proof-of-concept). Do: Self-hosted customers and partners should promptly apply the ServiceNow-provided security update or upgrade to a patched release, and hosted-instance administrators should verify their instance is running the patched build. Given the unauthenticated network vector and CVSS 4.0 score of 10.0, prioritize this patch even though no exploitation or public PoC is known. Monitor ServiceNow's advisory for updated guidance and indicators. | 10.0 | <1% |
| large≈ tens of thousands of instances across ServiceNow's enterprise customer base (hosted instances auto-patched; residual unpatched exposure concentrated in… | ||
| CVE-2026-6875 | Unauthenticated Remote Code Execution in ServiceNow AI Platform ServiceNow has patched a critical, unauthenticated remote code execution vulnerability (CWE-94, code injection) in the ServiceNow AI platform that is reachable over the network without credentials or user interaction, though exploitation requires certain circumstances to be met (CVSS 4.0 attack complexity is high). A remote attacker who successfully triggers the flaw can execute code within the ServiceNow platform, with potentially high impact on the confidentiality, integrity, and availability of the instance and its data. Both ServiceNow-hosted (SaaS) instances and self-hosted customer and partner deployments are affected; hosted instances were fixed via a centrally deployed security update, while self-hosted customers and partners must apply the provided security updates or patched family releases themselves. ServiceNow's advisory states it was not initially aware of exploitation, but subsequent security reporting indicates this pre-auth RCE has been exploited in the wild. There is no known public proof-of-concept and the flaw is not yet in CISA's KEV catalog, but EPSS assigns a 77.6% probability of exploitation within 30 days. Do: Self-hosted customers and partners should immediately apply the released security updates or upgrade to the patched family releases, as specific affected version numbers were not disclosed. Hosted customers should verify with ServiceNow that their instance received the centrally deployed update and confirm their current patch level. Given reports of in-the-wild exploitation, review instance logs for signs of unauthenticated code execution and restrict external access to instances where feasible. | 9.5 | 78% |
| massmillions of end users across tens of thousands of hosted and self-hosted ServiceNow instances (no public count of AI-platform-enabled instances) | ||
| CVE-2026-6876 | Unauthenticated Sandbox Escape Allows Code Execution in ServiceNow AI Platform CVE-2026-6876 is a sandbox escape in the ServiceNow AI Platform (CWE-94, CWE-693, CWE-1284) that allows an unauthenticated, network-based attacker to execute arbitrary code within the platform. Triggering requires no privileges and no user interaction, consistent with the CVSS 4.0 base of 10.0 (AV:N/PR:N/UI:N with high impact across confidentiality, integrity, and availability). Successful exploitation grants arbitrary code execution inside the platform and potentially more access to the ServiceNow AI Platform than intended. All deployments of the ServiceNow AI Platform are affected: ServiceNow has already deployed the remediation to its hosted (SaaS) instances and has provided the update to partners and self-hosted customers. ServiceNow is not currently aware of malicious exploitation, and no public proof-of-concept is known. Do: Self-hosted customers and partners should promptly apply the ServiceNow-provided security update or upgrade to a patched release, prioritizing internet-facing instances given unauthenticated network exploitability. Hosted (SaaS) customers should verify with ServiceNow that their instance was automatically remediated. No workarounds or public PoC are known; consult ServiceNow PSIRT advisories for the specific patched version numbers, which are not included in the source data. | 10.0 | <1% |
| large≈ tens of thousands of ServiceNow instances (hosted instances already centrally patched) | ||
| CVE-2026-74820 | Unauthenticated SQL Injection in ServiceNow AI Platform CVE-2026-74820 is a critical (CVSS 4.0: 10.0) SQL injection flaw (CWE-89) in the ServiceNow AI platform that an unauthenticated attacker can, in certain circumstances, trigger remotely over the network. Successful exploitation allows arbitrary SQL statements to be executed against the instance's underlying database, giving the attacker access to or the ability to modify instance data beyond what was intended, with the CVSS scoring indicating high impact to confidentiality, integrity, and availability. Any organization running an unpatched ServiceNow instance is affected, but ServiceNow has already deployed the security update to its hosted instances, so remaining exposure is concentrated among self-hosted customers and partners who must apply the provided update themselves. There is currently no known malicious exploitation: EPSS assigns a 0.2% probability of exploitation within 30 days, the flaw is not in CISA KEV, and no public proof-of-concept is known. Do: Self-hosted customers and partners should promptly apply the ServiceNow security update or upgrade to a patched release, and verify that any hosted instances received the automatic update. Review ServiceNow's related advisories covering the reported set of three CVSS 10.0 ServiceNow flaws (unauthenticated code execution and SQL injection) and apply the full patch bundle. Since no in-the-wild exploitation is known, patch urgently per vendor guidance and confirm instances are no longer running unpatched releases. | 10.0 | <1% |
| mass≈ millions of enterprise users across thousands of customer instances (ServiceNow serves thousands of enterprise customers, including a majority of the Fortune… |
Full article853 words · extracted from thehackernews.com · click to collapse
Swati KhandelwalAug 28, 2026Vulnerability / Cloud Security
ServiceNow has released patches for four security flaws impacting the ServiceNow AI Platform, three of them rated 10.0 on the CVSS scoring system and exploitable, in certain circumstances, by an unauthenticated attacker.
The company said it deployed a security update to hosted instances and provided the update to its partners and self-hosted customers, which leaves organizations that run their own instances to apply the fixes themselves.
The advisory was published on August 27, 2026, and the four vulnerabilities are listed below -
- CVE-2026-18885 (CVSS score: 10.0) - A code injection vulnerability in the GraphQL Composite Data API that could enable an unauthenticated user to execute arbitrary code and gain access to, or modify, instance data
- CVE-2026-18886 (CVSS score: 10.0) - An improper access control vulnerability in the system configuration image upload processor that could enable an unauthenticated user to create or modify instance data, resulting in privilege escalation
- CVE-2026-74820 (CVSS score: 10.0) - A SQL injection vulnerability reached through a dynamic schema ORDER BY clause that could enable an unauthenticated user to execute arbitrary SQL statements against the instance's underlying database
- CVE-2026-6876 (CVSS score: 8.7) - A sandbox escape in the Now Platform that could allow an unauthenticated user to execute arbitrary code
The three maximum-severity flaws share the vector CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H, describing a network-reachable attack of low complexity that requires no privileges and no user interaction, and that carries high impact to confidentiality, integrity, and availability in both the vulnerable component and the systems connected to it.
The advisory follows CVE-2026-6875, a pre-authentication sandbox escape in the same platform. Searchlight Cyber reported that flaw to ServiceNow on April 1, 2026. ServiceNow published the advisory for it on July 13.
Threat intelligence firm Defused said days after the July advisory that it was observing in-the-wild exploitation of CVE-2026-6875. It subsequently issued a correction stating that the captured payload matched Searchlight Cyber's published proof-of-concept (PoC) exploit.
"ServiceNow is aware of a cybersecurity company's recent publication regarding exploitation activity associated with a previously disclosed security vulnerability, identified as CVE-2026-6875," a ServiceNow spokesperson told The Hacker News. "Based on our investigation to date, we have not observed evidence that this activity is related to instances that ServiceNow hosts."
"We have provided updates and patches designed to address this issue, and we encourage our self-hosted and ServiceNow-hosted customers to apply the relevant patches if they have not already done so. In addition, we will continue to work directly with customers who need assistance in applying the patches," the spokesperson said.
The 10.0 ratings are ServiceNow's own. The company is the CVE Numbering Authority for its products, and since April 15, 2026, NIST has enriched only vulnerabilities that appear in CISA's Known Exploited Vulnerabilities catalog, affect federal government software, or are designated critical under Executive Order 14028.
None of the four flaws appeared in the catalog as of August 28, 2026, leaving ServiceNow's ratings as the only severity assessment on record.
ServiceNow rated all three of the new maximum-severity flaws at low attack complexity. It scored the sandbox escape reported exploited in July at 9.5 under the same version of the scoring system, with every metric identical to the three except attack complexity, which it set to high.
ServiceNow lists the following versions as affected in its August advisory -
- Xanadu - any version before Patch 11 Hot Fix 7a
- Yokohama - any version before Patch 12 Hot Fix 3b, and any version before Patch 13 Hot Fix 4
- Zurich - any version before Patch 7b Hot Fix 3, Patch 8 Hot Fix 5, Patch 9 Hot Fix 6, Patch 10 Hot Fix 2m (m-branch), Patch 10 Hot Fix 3 (standard), Patch 11, or Patch 12
- Australia - any version before Patch 2 Hot Fix 3, Patch 3 Hot Fix 2, Patch 3m, Patch 4, or Patch 5
The record for CVE-2026-18886 marks "Any version before Australia Patch 5" with a status of unknown, where the records for the other three mark the same version as affected. All four set a default product status of unaffected, so a release the list does not name falls outside the affected set.
ServiceNow describes CVE-2026-6876 as an issue that could allow an unauthenticated user to execute arbitrary code within the Now Platform, while the CVSS vector it assigned to the same flaw specifies PR:L, or low privileges required.
That vector also records no impact to systems beyond the vulnerable component, unlike the three rated 10.0.
ServiceNow said in each of the four records that it is not currently aware of exploitation. The Hacker News found no public exploit code for the three maximum-severity flaws as of August 28, 2026.
Searchlight Cyber had published no technical write-up for the flaws disclosed in August at the time of writing. Adam Kues, a security researcher at the firm, wrote in July that ServiceNow was "enhancing instance security by severely restricting the type of code that can run in sandbox contexts."
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2026/08/three-cvss-100-servicenow-flaws-could.html