Critical

ServiceNow, CVE-2026-18885, RCE, SQL Injection, Cloud, Enterprise

ServiceNow CVE-2026-18885: Three CVSS 10.0 Flaws

ServiceNow CVE-2026-18885 is one of three CVSS 10.0 flaws letting unauthenticated attackers run code and SQL on the AI Platform. Affected setups and the fix.

ServiceNow CVE-2026-18885 is one of three maximum-severity flaws (all CVSS 10.0) that ServiceNow patched on August 27, 2026, any of which can let an unauthenticated attacker execute arbitrary code or SQL against the ServiceNow AI Platform. The trio is CVE-2026-18885 (CWE-94 code injection in the GraphQL Composite Data API), CVE-2026-18886 (improper access control in the system configuration image upload processor, enabling privilege escalation), and CVE-2026-74820 (CWE-89 SQL injection reached through a dynamic schema ORDER BY clause). A fourth flaw, CVE-2026-6876 (CVSS 8.7), is a sandbox escape in the Now Platform.

ServiceNow said it deployed the update to hosted instances and provided it to partners and self-hosted customers, which means organizations running their own instances must apply the fixes themselves. That self-hosted gap is the exposure that matters, because ServiceNow sits at the center of IT service management, HR, and workflow data for large enterprises, so unauthenticated code and database access is close to a worst case. The three 10.0 flaws share the vector CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H, describing a network-reachable, low-complexity attack that needs no privileges and no user interaction and carries high impact to both the vulnerable component and connected systems.

Which ServiceNow flaws are affected and how do I fix them?

All four affect the ServiceNow AI Platform, and the fix is the security update ServiceNow published with its August 27 advisory. Hosted instances are already patched; self-hosted customers and partners must apply the update themselves, and given three of the four are unauthenticated 10.0s, that should be treated as an emergency.

CVE

CVSS

Type

CVE-2026-18885

10.0

Code injection (CWE-94), GraphQL Composite Data API

CVE-2026-18886

10.0

Improper access control, image upload, privilege escalation

CVE-2026-74820

10.0

SQL injection (CWE-89), dynamic schema ORDER BY

CVE-2026-6876

8.7

Sandbox escape, Now Platform

Why does the self-hosted distinction matter so much?

Because it splits customers into patched and exposed. ServiceNow can update its own cloud instances centrally, but self-hosted deployments only become safe when their operators act, and those are frequently the most customized, most integrated, and least quickly patched. This advisory also follows CVE-2026-6875, a separate pre-authentication sandbox escape in the same platform disclosed shortly before, so the Now Platform has been a live target, and defenders searching for exploitation should assume attention will follow three public 10.0s quickly.

Our read

Three unauthenticated 10.0s in a platform that holds an enterprise's workflow and identity data is the profile that does not wait for a leisurely patch window. The self-hosted gap is where continuous verification earns its place: the safe assumption is not "ServiceNow patched it" but "which of our instances are self-hosted, internet-reachable, and actually updated," and the two answers diverge exactly when it matters. Confirm the update is live on every self-hosted instance rather than trusting the advisory closed the door, because a maximum-severity, no-interaction flaw is the kind attackers reverse-engineer from the patch.

Reporting by The Hacker News; CVSS, CWE, and affected-component detail per the ServiceNow advisory and NVD. Sources linked above.

Related: ServiceNow CVE-2026-6875 exploited and How to prioritize vulnerabilities.

Liked this briefing? Share it:

More briefings

Related posts appear on the live page
Get the briefings first
Breaking security news, verified fast, with the one fact the headlines skip. No spam - unsubscribe anytime.