HomeCyber BalkansServiceNow Addresses Critical Vulnerabilities Allowing Unauthenticated RCE and SQL Injection

ServiceNow Addresses Critical Vulnerabilities Allowing Unauthenticated RCE and SQL Injection

Published on

spot_img

ServiceNow Issues Security Advisory Addressing Critical Vulnerabilities in Its AI Platform

In an important development concerning cybersecurity, ServiceNow has released security advisories detailing four significant vulnerabilities within its AI platform. Among these vulnerabilities are critical flaws that pose severe threats to the integrity and security of user data and application functionality. According to the advisories, these vulnerabilities can be exploited by unauthenticated attackers to execute arbitrary code, manipulate instance data, elevate privileges, or run SQL commands against the underlying databases, which dramatically increases the risk of data breaches and unauthorized access.

On August 27, 2026, the company documented these vulnerabilities in knowledge base article KB3152242. This article encompasses four specific vulnerabilities identified as CVE-2026-6876, CVE-2026-18885, CVE-2026-18886, and CVE-2026-74820. ServiceNow disclosed that it has proactively addressed each of these issues based on findings from both its internal security research and a responsible disclosure program. This initiative is commendable as it showcases the company’s commitment to safeguarding its customers and maintaining high security standards.

Although the advisory does not provide exhaustive technical details about the exploitation of these vulnerabilities, it does outline potential attack vectors that could allow unauthorized access beyond intended authorization limits. Consequently, ServiceNow has urged users and organizations to verify their platform version and ensure that all production instances are updated accordingly to mitigate these threats.

Among the vulnerabilities, CVE-2026-18885 and CVE-2026-18886 stand out as critical under the Common Vulnerability Scoring System (CVSS) version 4.0. Both vulnerabilities are categorized as code-injection flaws that affect the ServiceNow AI platform. Specifically, CVE-2026-18885 could potentially enable an unauthenticated attacker to execute arbitrary code on the ServiceNow platform under certain conditions. This opens up avenues for altering or accessing instance data in ways not intended by the platform’s design.

In a similar vein, CVE-2026-18886 could facilitate unauthorized creation or modification of instance data, resulting in potential privilege escalation. The differentiation between these two scenarios is crucial: while one presents a direct risk of code execution, the other involves unauthorized data operations that could enhance an attacker’s permissions. Both situations underline the urgency for a thorough review and immediate remediation, including an examination of platform access logs to identify any suspicious activities.

CVE-2026-74820 also carries a critical rating and pertains to SQL injection vulnerabilities within the ServiceNow AI platform. ServiceNow has cautioned that there are conditions under which an unauthenticated user could execute SQL statements against an instance’s underlying database. Should such an exploitation occur, there is a significant risk to data confidentiality, integrity, and overall business workflows, leading to major operational challenges.

Conversely, CVE-2026-6876 is rated as high and pertains to a sandbox escape on the Now Platform. This flaw poses the risk of enabling arbitrary code execution within the platform, which could lead to greater access than intended. Sandbox escapes represent a severe threat because they breach the isolation mechanisms designed to contain untrusted execution, amplifying the risk of exploitation.

ServiceNow has indicated that customers participating in its Patching Program have already received the necessary updates to counter these vulnerabilities. However, organizations are advised to independently verify the versions of their instances. The remediated versions include various patches and hotfixes across different releases, including Xanadu Patch 11 Hot Fix 7a, Yokohama Patch 12 Hot Fix 3b and Patch 13 Hot Fix 4, along with multiple updates in the Zurich release series and Australia Patches 2 through 5.

Administrators should meticulously compare their current deployments with the advisory details, ensure that the relevant patches or hotfixes are applied, and assess any potential exposure resulting from internet-accessible AI functions. In addition, security teams are encouraged to conduct comprehensive reviews of authentication logs, database activities, unusual modifications to instance records, and any privileged actions to identify signs of attempted exploitation.

In conclusion, swift and effective patching is crucial to maintaining the security infrastructure of ServiceNow’s ecosystem. With the increasing sophistication of cyber threats, organizations must remain vigilant and proactive in addressing vulnerabilities to thwart potential breaches and safeguard their sensitive information.

Source link

Latest articles

Mobile Banking Trojans Achieve Complete Device Control

Mobile Banking Malware Evolution: A Threat Landscape Report In 2025, the landscape of mobile banking...

CISA Adds Six Exploited Vulnerabilities to KEV Catalog

On August 26, the United States Cybersecurity and Infrastructure Security Agency (CISA) made significant...

Critical Flaw in WordPress Plugin Enables Unauthenticated Administrator Account Takeover

Critical Vulnerability Exposed in WPMU DEV Dashboard Plugin for WordPress A significant security issue has...

Russian APT BlueDelta Targets European Government with HOOKEDGE

Espionage Campaign by BlueDelta Targets European Governments: A Detailed Overview A recent report by Recorded...

More like this

Mobile Banking Trojans Achieve Complete Device Control

Mobile Banking Malware Evolution: A Threat Landscape Report In 2025, the landscape of mobile banking...

CISA Adds Six Exploited Vulnerabilities to KEV Catalog

On August 26, the United States Cybersecurity and Infrastructure Security Agency (CISA) made significant...

Critical Flaw in WordPress Plugin Enables Unauthenticated Administrator Account Takeover

Critical Vulnerability Exposed in WPMU DEV Dashboard Plugin for WordPress A significant security issue has...