ServiceNow AI Platform unauthenticated code injection (CVE-2026-18885)
ServiceNow's 27 August 2026 CVE record (CNA title: Unauthenticated Remote Code Execution in GraphQL Composite Data API) says it remediated a code-injection flaw in the ServiceNow AI Platform that could, in certain circumstances, let an unauthenticated user run arbitrary code and gain access to or change instance data beyond what was intended. ServiceNow scored it 10.0 (CVSS 4.0). Hosted instances received a vendor-deployed security update; partners and self-hosted customers were given the update. ServiceNow says it is not currently aware of malicious exploitation. Self-hosted operators should apply the August 2026 CVE advisory updates (KB3152242). Affected CNA rows include Xanadu, Yokohama, Zurich and Australia patch families listed on the CVE record. Distinct from CVE-2026-74820 (SQL injection) and CVE-2026-18886 (privilege escalation) on this desk.
- Product
- ServiceNow AI Platform
- Versions
- CNA-listed Xanadu, Yokohama, Zurich and Australia patch-family builds (see KB3152242)
- CVSS
- (CVSS 4.0, ServiceNow CNA)
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H - Exploited in Australia?
- unknown
- Patch to
- Hosted: vendor already deployed the update. Self-hosted/partners: apply August 2026 CVE advisory updates (KB3152242)
Primary: CVE-2026-18885 (ServiceNow CNA) · Vendor: ServiceNow August 2026 CVE advisory (KB3152242) · CVE: CVE-2026-18885, CVE-2026-74820, CVE-2026-18886 · CVE-2026-74820 (same-day SQL injection, 10.0)
