ServiceNow AI Platform unauthenticated SQL injection (CVE-2026-74820)
ServiceNow's 27 August 2026 CVE record says it remediated an unauthenticated SQL injection in the ServiceNow AI Platform that could, in certain circumstances, let an unauthenticated user run arbitrary SQL against the instance database and read or change data beyond what was intended. ServiceNow scored it 10.0 (CVSS 4.0). Hosted instances received a vendor-deployed security update; partners and self-hosted customers were given the update. ServiceNow says it is not currently aware of malicious exploitation. The same 27 August CNA batch includes CVE-2026-6876 (Now Platform sandbox escape, CVSS 4.0 8.7) and CVE-2026-18886 (AI Platform improper access control). Self-hosted operators should apply the August 2026 CVE advisory updates. Affected CNA rows include Xanadu, Yokohama, Zurich and Australia patch families listed on the CVE record.
- Product
- ServiceNow AI Platform (also Now Platform for CVE-2026-6876)
- Versions
- CNA-listed Xanadu, Yokohama, Zurich and Australia patch-family builds (see KB3152242)
- CVSS
- (CVSS 4.0, ServiceNow CNA)
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H - Exploited in Australia?
- unknown
- Patch to
- Hosted: vendor already deployed the update. Self-hosted/partners: apply August 2026 CVE advisory updates (KB3152242)
Primary: CVE-2026-74820 (ServiceNow CNA) · Vendor: ServiceNow August 2026 CVE advisory (KB3152242) · CVE: CVE-2026-74820, CVE-2026-6876, CVE-2026-18886 · CVE-2026-6876 (same-day Now Platform sandbox escape)
