CVE-2026-74820

10.0

ServiceNow · ServiceNow AI Platform

A SQL injection vulnerability in the ServiceNow AI platform allows unauthenticated remote attackers to execute arbitrary SQL commands, potentially leading to unauthorized data access or modification.

Executive summary

A critical SQL injection vulnerability in the ServiceNow AI Platform allows unauthenticated attackers to compromise database integrity and confidentiality.

Vulnerability

This vulnerability is a SQL injection flaw located within the ServiceNow AI platform, which permits an unauthenticated attacker to inject arbitrary SQL statements into the underlying database. The vulnerability requires no user interaction or prior authentication to exploit.

Business impact

The ability for an unauthenticated attacker to execute arbitrary SQL commands represents a catastrophic risk to organizational data. Successful exploitation could lead to full database compromise, including the unauthorized exfiltration of sensitive records, modification of business logic, or total loss of data integrity. With a CVSS score of 10.0, this vulnerability demands immediate attention to prevent severe reputational and operational damage.

Remediation

Immediate Action: Customers must immediately upgrade to the specific patched versions listed in the vendor advisory KB3152242, or ensure their hosted instances have received the automated updates deployed by ServiceNow.

Proactive Monitoring: Security teams should review database access logs for suspicious query patterns, such as unusual syntax or unexpected administrative commands, originating from unknown or external IP addresses.

Compensating Controls: Deploy a Web Application Firewall (WAF) with updated rulesets designed to detect and block SQL injection patterns, which can provide a temporary layer of protection while internal update cycles are completed.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

Given the critical CVSS severity of 10.0 and the unauthenticated nature of this vulnerability, immediate patching is required to secure the environment. Organizations should prioritize the verification of their current patch levels against the specific hot fix versions provided by ServiceNow to ensure full coverage against this vector.

More ServiceNow CVEs

Sources