SQL Injection Vulnerability in ServiceNow AI Platform
CVE-2026-74820

10CRITICAL

Key Information:

Vendor

Servicenow

Vendor
CVE Published:
27 August 2026

What is CVE-2026-74820?

A security vulnerability has been identified in ServiceNow's AI platform that allows an unauthenticated user to perform SQL injection attacks. In specific scenarios, an attacker could execute arbitrary SQL commands on the platform's underlying database, potentially altering or accessing sensitive instance data. ServiceNow has implemented a security update for hosted instances and has advised partners and self-hosted customers to apply the necessary updates. Although there is currently no evidence of exploitation, it is crucial for customers to promptly update their systems to protect against potential threats.

Affected Version(s)

ServiceNow AI Platform 0

ServiceNow AI Platform 0

ServiceNow AI Platform 0

References

CVSS V4

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.