ServiceNow AI Platform Patches Three Critical Pre-Auth Risks
What happened
ServiceNow released security fixes for multiple AI Platform vulnerabilities, including three issues rated CVSS 10.0. The flaws span code injection, privilege-related abuse paths, and SQL injection conditions that can be triggered without authentication in low-complexity scenarios.
Who is affected
Organizations running self-hosted ServiceNow AI Platform instances are the primary risk group because cloud-hosted instances were patched by ServiceNow.
Why it matters
ServiceNow is deeply integrated into IT, security, and business workflows. Critical pre-auth flaws in this layer can create high-impact risk, including unauthorized data access, integrity impact, and potential downstream process disruption.
Technical details
- CVE-2026-18885: pre-auth code injection (CVSS 10.0)
- CVE-2026-18886: pre-auth issue enabling privileged abuse and data impact (CVSS 10.0)
- CVE-2026-74820: SQL injection affecting instance data access/modification (CVSS 10.0)
- Additional issue: CVE-2026-6876 (high severity) affecting sandbox boundaries
- Exploitation status at publication: no confirmed active exploitation reported by vendor
- Patched release trains include updated hotfix lines across Xanadu, Yokohama, Zurich, and Australia branches
Recommended actions
- Apply the latest vendor hotfixes immediately on self-hosted instances.
- Prioritize externally reachable admin/API surfaces.
- Review access controls and segmentation around ServiceNow application tiers.
- Audit logs for anomalous unauthenticated requests, query abuse patterns, and unexpected configuration changes.
- Coordinate with change management and incident response teams to validate platform integrity after patching.
Sources
- https://www.bleepingcomputer.com/news/security/servicenow-warns-of-three-max-severity-security-vulnerabilities/
- https://support.servicenow.com/kb?id=kb_article_view&sysparm_article=KB3152242
