Junglewise Threat Intelligence

CVE-2026-18886: ServiceNow AI Platform improper access control vulnerability

CVE-2026-18886 · Severity: info · Published 2026-08-27

Technologies: ServiceNow AI Platform. Vendors: ServiceNow.

Executive brief

ServiceNow's AI platform contained an access control flaw that could allow unauthenticated users to create or modify instance data in certain circumstances, potentially bypassing security controls. The vulnerability has been patched and deployed to all hosted instances, with no known active exploitation reported.

Technical details

An improper access control vulnerability in the ServiceNow AI platform failed to properly restrict data modification operations. The flaw could enable an unauthenticated attacker to create or modify instance data beyond intended scope, resulting in privilege escalation. ServiceNow has deployed security updates to hosted instances and provided patches to partners and self-hosted customers. No exploitation in the wild has been identified.

Affected products

  • ServiceNow AI Platform

Timeline

  • 2026-08-27: disclosed
  • 2026-08-27: patched: Security update deployed to hosted instances; patches provided to partners and self-hosted customers

References