Code Injection Vulnerability in ServiceNow AI Platform
CVE-2026-18885
10CRITICAL
What is CVE-2026-18885?
A code injection vulnerability has been identified in the ServiceNow AI platform, allowing an unauthenticated user to execute arbitrary code under certain conditions. This could lead to unauthorized access or modification of instance data. In response, ServiceNow has provided a security update to protect hosted instances and has made updates available to partners and self-hosted customers. To mitigate risks, it is essential for users to apply the security patches promptly to safeguard their instances effectively.
Affected Version(s)
ServiceNow AI Platform 0
ServiceNow AI Platform 0
ServiceNow AI Platform 0
References
EPSS Score
7% chance of being exploited in the next 30 days.
CVSS V4
Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Adam Kues - Assetnote
