SB2026082823 - Multiple vulnerabilities in ServiceNow platform



SB2026082823 - Multiple vulnerabilities in ServiceNow platform

Published: August 28, 2026

Security Bulletin ID SB2026082823
CSH Severity
High
Patch available
YES
Number of vulnerabilities 4
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

High 75% Low 25%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 4 vulnerabilities.


1) Code Injection (CVE-ID: CVE-2026-6876)

CWE-ID: CWE-94 - Improper Control of Generation of Code ('Code Injection')

CVSSv4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to a sandbox escape in the Now Platform when processing crafted input within the platform sandbox. A remote attacker can trigger the sandbox escape to execute arbitrary code.

This may lead to more access to the Now Platform than intended.


2) Code Injection (CVE-ID: CVE-2026-18885)

CWE-ID: CWE-94 - Improper Control of Generation of Code ('Code Injection')

CVSSv4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary code and access or modify instance data.

The vulnerability exists due to code injection in the ServiceNow AI platform when handling crafted input in certain circumstances. A remote attacker can send crafted input to execute arbitrary code and access or modify instance data.


3) Code Injection (CVE-ID: CVE-2026-18886)

CWE-ID: CWE-94 - Improper Control of Generation of Code ('Code Injection')

CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to escalate privileges.

The vulnerability exists due to code injection in the ServiceNow AI platform when handling crafted input in certain circumstances. A remote attacker can send crafted input to create or modify instance data beyond what was intended to escalate privileges.


4) SQL injection (CVE-ID: CVE-2026-74820)

CWE-ID: CWE-89 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

CVSSv4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary SQL statements and access or modify instance data.

The vulnerability exists due to SQL injection in the ServiceNow AI platform when handling crafted input in certain circumstances. A remote attacker can send crafted input to execute arbitrary SQL statements and access or modify instance data.

The arbitrary SQL statements are executed against the instance's underlying database.


Remediation

Install update from vendor's website.