Improper Access Control in ServiceNow AI Platform
CVE-2026-18886

10CRITICAL

Key Information:

Vendor

Servicenow

Vendor
CVE Published:
27 August 2026

Badges

๐Ÿ‘พ Exploit Exists๐Ÿ“ฐ News Worthy

What is CVE-2026-18886?

An improper access control vulnerability was discovered in the ServiceNow AI platform, allowing an unauthorized user to potentially create or modify instance data beyond designated permissions. This issue could lead to privilege escalation, compromising the integrity of instance configurations. ServiceNow has issued a security update that addresses this vulnerability, and it is crucial for users to apply these updates promptly to safeguard their instances.

Affected Version(s)

ServiceNow AI Platform 0

ServiceNow AI Platform 0

ServiceNow AI Platform 0

News Articles

Three CVSS 10.0 ServiceNow Flaws Could Let Unauthenticated Attackers Execute Code and SQL

ServiceNow patched four AI Platform flaws, including three CVSS 10.0 bugs that can enable unauthenticated code execution or data access.

1 month ago

References

EPSS Score

5% chance of being exploited in the next 30 days.

CVSS V4

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • ๐Ÿ‘พ

    Exploit known to exist

  • ๐Ÿ“ฐ

    First article discovered by The Hacker News

  • Vulnerability published

  • Vulnerability Reserved

Credit

Kevin Gervot - Assetnote
.