Code Injection Vulnerability in ServiceNow AI Platform
CVE-2026-18885
10CRITICAL
What is CVE-2026-18885?
A code injection vulnerability has been identified in the ServiceNow AI platform, allowing an unauthenticated user to execute arbitrary code under certain conditions. This could lead to unauthorized access or modification of instance data. In response, ServiceNow has provided a security update to protect hosted instances and has made updates available to partners and self-hosted customers. To mitigate risks, it is essential for users to apply the security patches promptly to safeguard their instances effectively.
Affected Version(s)
ServiceNow AI Platform 0
ServiceNow AI Platform 0
ServiceNow AI Platform 0
