Improper Access Control in ServiceNow AI Platform
CVE-2026-18886

10CRITICAL

Key Information:

Vendor

Servicenow

Vendor
CVE Published:
27 August 2026

What is CVE-2026-18886?

An improper access control vulnerability was discovered in the ServiceNow AI platform, allowing an unauthorized user to potentially create or modify instance data beyond designated permissions. This issue could lead to privilege escalation, compromising the integrity of instance configurations. ServiceNow has issued a security update that addresses this vulnerability, and it is crucial for users to apply these updates promptly to safeguard their instances.

Affected Version(s)

ServiceNow AI Platform 0

ServiceNow AI Platform 0

ServiceNow AI Platform 0

References

CVSS V4

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Kevin Gervot - Assetnote
.