Code Injection in ServiceNow - CVE-2026-18885

 

Code Injection in ServiceNow - CVE-2026-18885

Published: August 28, 2026


Vulnerability identifier: #VU146029
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-18885
CWE-ID: CWE-94
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code and access or modify instance data.

The vulnerability exists due to code injection in the ServiceNow AI platform when handling crafted input in certain circumstances. A remote attacker can send crafted input to execute arbitrary code and access or modify instance data.


Affected software

ServiceNow

How to mitigate CVE-2026-18885

Install security update from vendor's website.

ServiceNow - addressed in versions Australia Patch 2 Hot Fix 3, Australia Patch 3 Hot Fix 2, Australia Patch 3m, Australia Patch 4, Zurich Patch 7b Hot Fix 3, Zurich Patch 8 Hot Fix 5, Zurich Patch 9 Hot Fix 6, Zurich Patch 10 Hot Fix 2m, Zurich Patch 10 Hot Fix 3, Xanadu Patch 11 HotFix 7a, Zurich Patch 11

External References

Related Security Bulletins