Multiple security vulnerabilities have been identified in ServiceNow's AI Platform that can be exploited in code injection, SQL injection, and privilege escalation attacks. The affected platform is an enterprise-grade Platform-as-a-Service (PaaS) used to integrate AI into core enterprise workflows and powers more than 100,000 enterprise AI apps at 85% of all Fortune 500 companies. Affected version ranges are not explicitly stated in the article.
CVE-2026-18885: A code injection vulnerability that allows attackers to execute arbitrary code. The vulnerability can be exploited by unauthenticated threat actors in low-complexity attacks that don't require user interaction.[/subscribe_to_unlock_form]
Multiple security vulnerabilities have been identified in ServiceNow's AI Platform that can be exploited in code injection, SQL injection, and privilege escalation attacks. The affected platform is an enterprise-grade Platform-as-a-Service (PaaS) used to integrate AI into core enterprise workflows and powers more than 100,000 enterprise AI apps at 85% of all Fortune 500 companies. Affected version ranges are not explicitly stated in the article.
CVE-2026-18885: A code injection vulnerability that allows attackers to execute arbitrary code. The vulnerability can be exploited by unauthenticated threat actors in low-complexity attacks that don't require user interaction.[emaillocker id="1283"]
CVE-2026-18886: A code injection weakness that enables attackers to escalate privileges.
CVE-2026-74820): SQL injection attacks allow threat actors to access or modify instance data.
CVE-2026-6876: A sandbox escape security issue affecting the same platform allows attackers with basic privileges to gain remote code execution on targeted systems.
CVE-2024-4879: CVE-2024-5178, and CVE-2024-5217) using publicly available exploits to breach private firms and government agencies worldwide in data theft attacks.
CVE-2024-5178: And CVE-2024-5217) using publicly available exploits to breach private firms and government agencies worldwide in data theft attacks.
CVE-2024-5217: using publicly available exploits to breach private firms and government agencies worldwide in data theft attacks.
CVE-2026-6875: a pre-auth sandbox escape in the ServiceNow AI Platform.
These vulnerabilities collectively present a significant risk to ServiceNow customers.
We recommend you to update ServiceNow AI Platform to given version link: https://www.bleepingcomputer.com/news/security/servicenow-warns-of-three-max-severity-security-vulnerabilities/
The following reports contain further technical details:
[/emaillocker]