ServiceNow Addresses 3 Critical Code Injection Flaws with Security Updates

www.news4hackers.com-servicenow-addresses-3-critical-code-injection-flaws-with-security-updates-servicenow-addresses-3-critical-code-injection-flaws-with-security-updates

ServiceNow has released updates addressing four security flaws in its AI platform, including three critical code injection vulnerabilities rated with a maximum severity score of 10/10 on the Common Vulnerability Scoring System.

Vulnerability Details

The first flaw, designated CVE-2026-18885, enables unauthorized execution of arbitrary code within the ServiceNow environment under specific conditions. Exploitation of this vulnerability could allow attackers to access and alter data without requiring authentication or user interaction, according to the company’s security advisory.

CVE-2026-18886

A second critical issue, CVE-2026-18886, involves improper access control mechanisms that could permit adversaries to create or modify arbitrary data and escalate privileges.

CVE-2026-74820

The third critical vulnerability, CVE-2026-74820, is an SQL injection flaw allowing attackers to execute untrusted SQL commands against the underlying database. This could lead to unauthorized access or modification of instance data beyond intended permissions.

CVE-2026-6876

A fourth issue, CVE-2026-6876, carries a CVSS score of 8.7 and represents a sandbox escape vulnerability that could enable code execution within the Now Platform without requiring authentication. The flaw could grant attackers expanded access to system resources.

Patches and Recommendations

ServiceNow has deployed patches for all four vulnerabilities across its hosted environments and provided hotfixes for self-hosted instances, urging customers to implement them immediately. The hotfixes apply to the Xanadu, Yokohama, Zurich, and Australia releases.

Industry experts emphasize the urgency of applying these updates, noting that attackers often exploit newly disclosed vulnerabilities rapidly. A security professional highlighted that organizations managing self-hosted ServiceNow systems face delays in patch deployment, creating a window for potential exploitation.

The advisory specifically warns of risks associated with unpatched GraphQL Composite Data API code injection flaws and SQL injection vulnerabilities, which could compromise sensitive data such as HR records, vendor onboarding systems, and financial approval workflows. The expert advised security teams to treat this update as an immediate priority rather than adhering to standard patch cycles.

Conclusion

The company’s advisory underscores the importance of mitigating these flaws to prevent unauthorized access and data integrity breaches.



About Author

en_USEnglish