HomeMalware & ThreatsServiceNow Addresses Three Critical Flaws in Its AI Platform

ServiceNow Addresses Three Critical Flaws in Its AI Platform

Published on

spot_img

Artificial Intelligence & Machine Learning,
Next-Generation Technologies & Secure Development

Unauthenticated Attackers Could Execute Code, Alter Data, Gain Privileges

ServiceNow Addresses Three Critical Flaws in Its AI Platform
Image: Shutterstock/ISMG

ServiceNow has recently announced that it has remedied four vulnerabilities within its artificial intelligence platform, which includes three flaws of critical significance. These vulnerabilities can potentially be exploited by unauthorized individuals without the need for authentication.

The three critical vulnerabilities each received a Common Vulnerability Scoring System (CVSS) score of 10, which is the highest possible rating. This alarming rating indicates that attackers could execute code, manipulate data, or even gain elevated privileges through these vulnerabilities. Despite the severity, ServiceNow has stated that they have no knowledge of these vulnerabilities being actively exploited in the wild.

ServiceNow published an original advisory detailing these issues on a Thursday and subsequently provided an update the following Tuesday. The vulnerabilities were uncovered through the company’s security research efforts as well as its responsible disclosure programs. Importantly, these vulnerabilities were remediated independently by ServiceNow, which underscores the company’s proactive security measures.

One of the critical flaws identified is particularly concerning. Tracked under the identifier CVE-2026-18885, this vulnerability could allow an unauthenticated attacker to carry out remote code execution. Under specific conditions that have not been explicitly disclosed, the attacker could also gain unauthorized access to or modify instance data, which raises additional concerns about data integrity and security.

Another critical vulnerability, known as CVE-2026-18886, poses an access control issue. This flaw enables an attacker who has not logged into the system to create or modify data that should otherwise be restricted. Consequently, there exists the potential for these attackers to gain elevated privileges within a ServiceNow instance, which could lead to more extensive system compromises.

The final critical vulnerability, noted as CVE-2026-74820, is classified as an SQL injection flaw. This vulnerability could allow an attacker, without the need for authentication, to issue unauthorized commands to the database that underpins a ServiceNow instance. The implications of this flaw are concerning, as it could lead to the unauthorized exposure or alteration of sensitive data.

SQL injection is a prevalent issue that arises when an application does not adequately separate user-supplied input from the commands sent to a database. In this specific instance, the vulnerability is related to how ServiceNow constructs part of its database queries, making it particularly susceptible to exploitation.

A fourth vulnerability, designated as CVE-2026-6876, is a high-severity flaw that could grant code the ability to escape a restricted environment intended to contain it. Known as a sandbox escape vulnerability, this flaw carries a CVSS score of 8.7 and affects the core cloud platform that ServiceNow operates for running business applications and workflows. The repercussions of this flaw may allow an unauthorized user to execute arbitrary code within the platform, potentially leading to breaches of confidential information.

ServiceNow has asserted that its customers should have received the necessary updates to address these vulnerabilities. Organizations are encouraged to verify the protection of their instances by comparing installed versions with the remediation levels outlined by the company in their advisories.

The patched releases encompass various ServiceNow families—namely Xanadu, Yokohama, Zurich, and Australia. Self-hosted customers who have not yet updated are urged to install the appropriate fixes or upgrade to a patched release promptly to mitigate any risks.

While ServiceNow has opted not to disclose the complete details of how these vulnerabilities could be exploited, the company maintains that researchers who responsibly report security issues may choose to publish their findings publicly at a later date. This strategic approach embodies the ongoing discourse in the cybersecurity field concerning vulnerability disclosure and the balancing act between public safety and security research.

Source link

Latest articles

CrowdStrike Introduces New Cyber Frontier AI Models and Agentic Security System

CrowdStrike and Nvidia Join Forces to Enhance Cybersecurity with SafeMind System In an ambitious move...

Attackers Steal METR API Key, Resulting in $600,000 Loss in AI Credits

Significant API Breach at METR: Stolen Credentials Lead to High-Stakes Abuse In a recent incident,...

The Hunt-to-Detection Gap: Selecting an AI Threat Hunting Solution for 2026

In the rapidly evolving field of cybersecurity, organizations increasingly seek reliable AI threat hunting...

OpenClaw Implements Comprehensive Overhaul and Enhances Security Controls Across Its Agent Platform

OpenClaw has recently unveiled its most significant update to date, heralded as a transformative...

More like this

CrowdStrike Introduces New Cyber Frontier AI Models and Agentic Security System

CrowdStrike and Nvidia Join Forces to Enhance Cybersecurity with SafeMind System In an ambitious move...

Attackers Steal METR API Key, Resulting in $600,000 Loss in AI Credits

Significant API Breach at METR: Stolen Credentials Lead to High-Stakes Abuse In a recent incident,...

The Hunt-to-Detection Gap: Selecting an AI Threat Hunting Solution for 2026

In the rapidly evolving field of cybersecurity, organizations increasingly seek reliable AI threat hunting...