CVE-2026-18886
10.0ServiceNow · ServiceNow AI Platform
An improper access control vulnerability in the ServiceNow AI platform allows unauthenticated users to create or modify instance data, potentially leading to full privilege escalation.
Executive summary
This critical vulnerability in the ServiceNow AI platform allows unauthenticated remote attackers to modify instance data and escalate privileges, posing a severe risk to organizational data integrity.
Vulnerability
The flaw is an improper access control vulnerability that permits an unauthenticated attacker to interact with the ServiceNow AI platform to create or modify data, resulting in privilege escalation.
Business impact
Successful exploitation grants an unauthenticated attacker the ability to alter critical instance data, which can lead to a total compromise of the platform's confidentiality, integrity, and availability. Given the CVSS score of 10.0, this represents the highest possible severity, potentially allowing attackers to gain administrative control over the entire ServiceNow environment and associated business processes.
Remediation
Immediate Action: Upgrade immediately to the specified patched releases or hot fixes provided by ServiceNow in their security advisory KB3152242.
Proactive Monitoring: Audit system logs for unauthorized configuration changes, anomalous data creation patterns, or unexpected administrative activity within the AI platform.
Compensating Controls: Implement strict network-level access controls to restrict exposure of the AI platform interface to trusted IP ranges until the patch can be applied.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
Due to the critical nature of this vulnerability and the potential for full administrative takeover of the ServiceNow instance, organizations must prioritize the application of the vendor-provided patches. Verify the specific version of the ServiceNow AI platform in your environment and apply the required hot fix immediately to prevent unauthorized data manipulation and privilege escalation.
More ServiceNow CVEs
Sources
Originally found and disclosed by Kevin Gervot - Assetnote, per the CVE Program record.