Code Injection Vulnerability in ServiceNow AI Platform
CVE-2026-18885

10CRITICAL

Key Information:

Vendor

Servicenow

Vendor
CVE Published:
27 August 2026

What is CVE-2026-18885?

A code injection vulnerability has been identified in the ServiceNow AI platform, allowing an unauthenticated user to execute arbitrary code under certain conditions. This could lead to unauthorized access or modification of instance data. In response, ServiceNow has provided a security update to protect hosted instances and has made updates available to partners and self-hosted customers. To mitigate risks, it is essential for users to apply the security patches promptly to safeguard their instances effectively.

Affected Version(s)

ServiceNow AI Platform 0

ServiceNow AI Platform 0

ServiceNow AI Platform 0

References

CVSS V4

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Adam Kues - Assetnote
.