SQL Injection Vulnerability in ServiceNow AI Platform
CVE-2026-74820
10CRITICAL
What is CVE-2026-74820?
A security vulnerability has been identified in ServiceNow's AI platform that allows an unauthenticated user to perform SQL injection attacks. In specific scenarios, an attacker could execute arbitrary SQL commands on the platform's underlying database, potentially altering or accessing sensitive instance data. ServiceNow has implemented a security update for hosted instances and has advised partners and self-hosted customers to apply the necessary updates. Although there is currently no evidence of exploitation, it is crucial for customers to promptly update their systems to protect against potential threats.
Affected Version(s)
ServiceNow AI Platform 0
ServiceNow AI Platform 0
ServiceNow AI Platform 0
