ServiceNow Patches 4 Flaws in AI Platform, Three Rated CVSS 10.0
TechNadu · x · 2026-08-29
ServiceNow has released patches for four security vulnerabilities impacting its ServiceNow AI Platform, three of which are rated critical with a CVSS score of 10.0.
Vulnerability Details:
- CVE-2026-18885 (CVSS 10.0): Code injection in the GraphQL Composite Data API allowing unauthenticated arbitrary code execution and data access/modification.
- CVE-2026-18886 (CVSS 10.0): Improper access control in the system configuration image upload processor leading to privilege escalation and data modification by unauthenticated users.
- CVE-2026-74820 (CVSS 10.0): SQL injection via a dynamic schema ORDER BY clause enabling arbitrary SQL statement execution.
- CVE-2026-6876 (CVSS 8.7): Sandbox escape in the Now Platform allowing arbitrary code execution.
Affected releases span Xanadu, Yokohama, Zurich, and Australia. Hosted instances have been updated, while self-hosted customers must apply the fixes manually.
Related event: ServiceNow Patches Four AI Platform Flaws, Three Rated CVSS 10.0(2 posts)→
More from Safety
- Aligning agent interactions is orders of magnitude harder than single agents — Afinetheorem · 2026-08-30
- METR Researcher: Watch Out for Third-Party Oversight Theater — RichardMCNgo · 2026-08-30
- Evidence Suggests Agent Swarms Won't Spontaneously Solve Human Issues — LuizaJarovsky · 2026-08-30
- Opinion: AI-Driven Bioweapons Could Target Food Systems, Starve Nations — PierceLilholt · 2026-08-30
- AI Safety Circle Underestimated Risks; METR Barred from Probing OpenAI — DavidSKrueger · 2026-08-30
- Experts call for regulation on superintelligence and kill switches for strong open models — Afinetheorem · 2026-08-30