Vulnerability
Published 2026-08-27
Verified 2026-09-19

ServiceNow AI Platform unauthenticated privilege escalation (CVE-2026-18886)

ServiceNow's 27 August 2026 CVE record (CNA title: Unauthenticated Privilege Escalation via System Configuration Image Upload Processor) says it remediated an improper access control flaw in the ServiceNow AI Platform that could, in certain circumstances, let an unauthenticated user create or modify instance data beyond what was intended, resulting in privilege escalation. ServiceNow scored it 10.0 (CVSS 4.0). Hosted instances received a vendor-deployed security update; partners and self-hosted customers were given the update. ServiceNow says it is not currently aware of exploitation against ServiceNow instances. Self-hosted operators should apply the August 2026 CVE advisory updates (KB3152242). Affected CNA rows include Xanadu, Yokohama, Zurich and Australia patch families listed on the CVE record. Distinct from CVE-2026-74820 (SQL injection) and CVE-2026-18885 (code injection) on this desk.

Product
ServiceNow AI Platform
Versions
CNA-listed Xanadu, Yokohama, Zurich and Australia patch-family builds (see KB3152242)
CVSS
(CVSS 4.0, ServiceNow CNA)
Exploited in Australia?
unknown
Patch to
Hosted: vendor already deployed the update. Self-hosted/partners: apply August 2026 CVE advisory updates (KB3152242)

Primary: CVE-2026-18886 (ServiceNow CNA) · Vendor: ServiceNow August 2026 CVE advisory (KB3152242) · CVE: CVE-2026-18886, CVE-2026-74820, CVE-2026-18885 · CVE-2026-18885 (same-day code injection, 10.0)

vulnerabilities cloud ai