Improper Access Control in ServiceNow AI Platform
CVE-2026-18886
10CRITICAL
Key Information:
- Vendor
Servicenow
- Status
- Vendor
- CVE Published:
- 27 August 2026
Badges
๐พ Exploit Exists๐ฐ News Worthy
What is CVE-2026-18886?
An improper access control vulnerability was discovered in the ServiceNow AI platform, allowing an unauthorized user to potentially create or modify instance data beyond designated permissions. This issue could lead to privilege escalation, compromising the integrity of instance configurations. ServiceNow has issued a security update that addresses this vulnerability, and it is crucial for users to apply these updates promptly to safeguard their instances.
Affected Version(s)
ServiceNow AI Platform 0
ServiceNow AI Platform 0
ServiceNow AI Platform 0
News Articles
References
EPSS Score
5% chance of being exploited in the next 30 days.
CVSS V4
Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
- ๐พ
Exploit known to exist
- ๐ฐ
First article discovered by The Hacker News
Vulnerability published
Vulnerability Reserved
Credit
Kevin Gervot - Assetnote
