CVE-2026-18885
10.0ServiceNow · ServiceNow AI Platform
A code injection vulnerability in the ServiceNow AI Platform allows unauthenticated attackers to execute arbitrary code and modify instance data.
Executive summary
A critical code injection vulnerability in the ServiceNow AI Platform could allow unauthenticated remote attackers to achieve full system compromise.
Vulnerability
This is a code injection flaw within the ServiceNow AI component that can be triggered by an unauthenticated user over the network. The vulnerability permits the execution of arbitrary code, granting the attacker the ability to read, modify, or delete sensitive instance data.
Business impact
The potential for unauthenticated remote code execution represents a catastrophic risk to organizational security. Successful exploitation could lead to total loss of confidentiality, integrity, and availability of the ServiceNow instance, which often serves as a central repository for sensitive corporate data and IT workflows. Given the CVSS score of 10.0, this vulnerability must be treated as a highest-priority incident.
Remediation
Immediate Action: Update the ServiceNow AI Platform to the relevant patched release specified in the vendor advisory (KB3152242) immediately.
Proactive Monitoring: Review system and application logs for suspicious inbound requests or unexpected process execution originating from the AI platform module.
Compensating Controls: Deploy strict network access controls or Web Application Firewall rules to restrict access to the affected ServiceNow endpoints until the patch can be verified.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the critical severity of this vulnerability and the potential for complete system takeover, administrators should prioritize the application of the provided security patches. Verify the specific version requirements for your environment against the official ServiceNow support documentation to ensure full coverage, as multiple release branches require specific hotfixes. Failure to act promptly could leave the platform exposed to unauthorized data access and manipulation.
More ServiceNow CVEs
Sources
Originally found and disclosed by Adam Kues - Assetnote, per the CVE Program record.