Vulnerability identifier: #VU146031
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-74820
CWE-ID: CWE-89
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary SQL statements and access or modify instance data.
The vulnerability exists due to SQL injection in the ServiceNow AI platform when handling crafted input in certain circumstances. A remote attacker can send crafted input to execute arbitrary SQL statements and access or modify instance data.
The arbitrary SQL statements are executed against the instance's underlying database.
Affected software
ServiceNow
How to mitigate CVE-2026-74820
Install security update from vendor's website.
ServiceNow - addressed in versions Australia Patch 2 Hot Fix 3, Australia Patch 3 Hot Fix 2, Australia Patch 3m, Australia Patch 4, Zurich Patch 7b Hot Fix 3, Zurich Patch 8 Hot Fix 5, Zurich Patch 9 Hot Fix 6, Zurich Patch 10 Hot Fix 2m, Zurich Patch 10 Hot Fix 3, Xanadu Patch 11 HotFix 7a, Zurich Patch 11
External References
Related Security Bulletins