CVE-2026-18886

Published Aug 27, 2026

Last updated 2 days ago

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-18886 is an improper access control vulnerability found within the ServiceNow AI Platform. This flaw allows an unauthenticated attacker to create or modify instance data beyond its intended scope. Successful exploitation of this vulnerability can lead to privilege escalation, enabling malicious actors to gain elevated access and control over the affected ServiceNow instance. The vulnerability is reachable over the network against internet-exposed ServiceNow instances without requiring credentials.

Description
ServiceNow has remediated an improper access control vulnerability that was identified in the ServiceNow AI platform. This vulnerability could enable an unauthenticated user, in certain circumstances, to create or modify instance data beyond what was intended, resulting in privilege escalation.  ServiceNow deployed a security update to hosted instances and ServiceNow provided the update to our partners and self-hosted customers. We are not currently aware of exploitation against ServiceNow instances.  We recommend customers promptly apply appropriate updates or upgrade to a patched release if they have not already done so.
Source
psirt@servicenow.com
NVD status
Received

Risk scores

CVSS 4.0

Type
Secondary
Base score
10
Impact score
-
Exploitability score
-
Vector string
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity
CRITICAL

Weaknesses

134c704f-9b21-4f2e-91b3-4a467353bcc0
CWE-284

Social media

Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.

Hype score

2

  1. https://t.co/XGyPIY3VaE ServiceNow has remediated a SQL injection vulnerability a code injection vulnerability a sandbox escape security issue CVE-2026-6876, CVE-2026-18886, CVE-2026-74820 #ITSecurity

    @seaarepea

    30 Aug 2026

    42 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. ServiceNow'da üç kritik (CVSS 10.0) güvenlik açığı! Bulunan açıklardan CVE-2026-18885 kod çalıştırmaya, CVE-2026-18886 yetki yükseltmeye, CVE-2026-74820 ise SQL enjeksiyonuyla veri okuma ve değiştirmeye izin veriyor. https://t.co/fE5KzEEpii https://t.co/lPOHizxF

    @Siber_Bulten

    30 Aug 2026

    807 Impressions

    0 Retweets

    0 Likes

    3 Bookmarks

    0 Replies

    0 Quotes

  3. August 2026 CVE Advisory Notification - Security - Now Support Portal What you need to know: On August 27, 2026, ServiceNow issued CVE-2026-6876, CVE-2026-18885, CVE-2026-18886, and CVE-2026-74820 regarding the underlying logic that allowed for the reported security issues. If

    @VistemSolutions

    30 Aug 2026

    38 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. ServiceNow patched three CVSS 10.0 vulnerabilities August 28. All three: unauthenticated code injection or SQL injection in the AI Platform. CVE-2026-18885, CVE-2026-18886, CVE-2026-74820. Every internet-facing instance vulnerable until patched. #Cybersecurity

    @McM1Alex

    29 Aug 2026

    53 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. 🚨 CYBERSÉCURITÉ — 3 FAILLES CRITIQUES CVSS 10.0 DANS SERVICENOW ServiceNow a publié le 27 août 2026 des correctifs pour plusieurs vulnérabilités majeures de sa plateforme AI, dont trois classées 10/10 : • CVE-2026-18885 : exécution de code arbitraire • CVE-2026

    @ActuX_off

    29 Aug 2026

    47 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  6. Security Bulletin: Multiple Critical Vulnerabilities in ServiceNow AI Platform - Three critical ServiceNow AI Platform vulnerabilities (CVE-2026-18885, CVE-2026-18886, CVE-2026-74820) may enable code injection, privilege escalation, or SQL inj... https://t.co/HQsgwH5UTu

    @RedLegg

    28 Aug 2026

    42 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  7. 🚨 ServiceNow just disclosed 3 CVSS 10.0 vulnerabilities that need immediate attention. No authentication. No user interaction. Low attack complexity. CVE-2026-18885 can enable arbitrary code execution. CVE-2026-18886 can enable privilege escalation. CVE-2026-74820 can enable

    @thecybersecguru

    28 Aug 2026

    69 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  8. 💀 Three ServiceNow AI Platform flaws rated CVSS 10.0 CVE-2026-18885, CVE-2026-18886, CVE-2026-74820 — unauthenticated code & SQL injection in Xanadu/Yokohama releases. 🔗 https://t.co/ZlwhR6wbuo

    @CyberOSINTIO

    28 Aug 2026

    11 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  9. 🚨 SERVICE NOW USERS: PATCH THIS NOW. 3 new CVSS 10.0 vulnerabilities could let unauthenticated attackers cross critical security boundaries: 🔴 CVE-2026-18885 — Code injection / arbitrary code execution 🔴 CVE-2026-18886 — Privilege escalation / data modification

    @thecybersecguru

    28 Aug 2026

    86 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  10. Warning: Multiple vulnerabilities in #ServiceNow. #CVE-2026-6876 #CVE-2026-18885 #CVE-2026-18886 #CVE-2026-74820 CVSS: 8.7 CVSS: 10 These vulnerabilities combined can lead to a full system compromise. Read our advisory: https://t.co/dbEQKPJO28 and #Patch #Patch #Patch

    @CCBalert

    28 Aug 2026

    302 Impressions

    0 Retweets

    0 Likes

    1 Bookmark

    0 Replies

    0 Quotes

  11. 🚨🚨🚨 CVE-2026-6876, CVE-2026-18885, CVE-2026-18886, CVE-2026-74820 August 2026 CVE Advisory Notification - Security ServiceNow Posture https://t.co/KsNPftCqPv

    @autumn_good_35

    28 Aug 2026

    314 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  12. ServiceNow disclosed four critical vulnerabilities in Now Platform and AI Platform, including unauthenticated code injection via GraphQL API and SQL injection flaws. CVE-2026-18885 allows remote code execution and data tampering without credentials. CVE-2026-18886 enables

    @WorldCyberNewsX

    28 Aug 2026

    7 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  13. ServiceNow patched CVE-2026-18885, CVE-2026-18886, and CVE-2026-74820, code injection and SQL injection flaws rated CVSS 10, plus a CVSS 8.7 bug. #ServiceNow #CodeInjection #SQLInjection #CVE #InfoSec https://t.co/hgTi9FD49L

    @Daily_CyberSec

    28 Aug 2026

    778 Impressions

    4 Retweets

    9 Likes

    7 Bookmarks

    0 Replies

    0 Quotes