← All articles

Three critical ServiceNow flaws let unauthenticated attackers run code and SQL

ServiceNow patched four flaws in its widely used AI Platform, three of them scored 10.0 and exploitable by an unauthenticated attacker with no user interaction. The first, CVE-2026-18885, is a code injection in the GraphQL Composite Data API that allows arbitrary code execution and access to instance data. The second, CVE-2026-18886, is an access-control flaw in the configuration image-upload processor that lets an attacker create or modify data and escalate privileges. The third, CVE-2026-74820, is a SQL injection allowing arbitrary queries against the instance database. ServiceNow fixed hosted instances itself, but self-managed customers must apply the updates. No exploitation of these three has been reported yet.

Check
Self-hosted ServiceNow customers should apply the platform updates immediately, since ServiceNow only patched its own hosted instances, and confirm production instances are on a fixed version.
Affected
Organizations running the ServiceNow AI Platform, especially self-managed instances (CVE-2026-18885, CVE-2026-18886, CVE-2026-74820); unauthenticated attackers can execute code, manipulate data, escalate privileges, or run arbitrary SQL with no interaction.
Fix
Patch self-hosted instances now, restrict network access to ServiceNow where possible, review logs for suspicious GraphQL requests, unexpected configuration or data changes, and anomalous database queries, and prioritize internet-reachable instances.