Three CVSS 10.0 ServiceNow Flaws Could Let Unauthenticated Attackers Execute Code and SQL
ServiceNow has released security patches for four critical vulnerabilities in its AI Platform, including three rated at 10.0 CVSS, that could allow unauthenticated attackers to execute code, create or modify instance data, and potentially gain access to underlying databases. While ServiceNow states it’s not currently aware of exploitation, a security firm, Searchlight Cyber, had published a proof-of-concept exploit for one of the vulnerabilities (CVE-2026-6875) in July. The company urges self-hosted and ServiceNow-hosted customers to apply the relevant patches immediately.
ServiceNow has released security patches to address four critical vulnerabilities within its AI Platform, including three rated at 10.0 on the CVSS scoring system. These flaws could enable unauthenticated attackers to execute arbitrary code, create or modify instance data, and potentially gain access to the underlying database. The vulnerabilities are present in versions of Xanadu, Yokohama, Zurich, and Australia.
CVE-2026-18885 allows an unauthenticated user to execute code and access instance data via a GraphQL Composite Data API. CVE-2026-18886 enables an unauthenticated user to create or modify instance data through an improper access control mechanism in the system configuration image upload processor. CVE-2026-74820 allows an unauthenticated user to execute arbitrary SQL statements against the instance’s database via a dynamic schema ORDER BY clause.
Searchlight Cyber reported CVE-2026-6875 to ServiceNow on April 1, 2026, and subsequently published a proof-of-concept exploit in July. ServiceNow confirmed that it is not currently aware of any exploitation activity related to these vulnerabilities, even though Searchlight Cyber’s PoC matched the reported activity. The vulnerabilities are present in versions of Xanadu, Yokohama, Zurich, and Australia.
ServiceNow’s own CVSS ratings are the only severity assessment available, as NIST has not yet enriched the vulnerabilities in CISA’s Known Exploited Vulnerabilities catalog. The company encourages self-hosted and ServiceNow-hosted customers to apply the relevant patches to mitigate these risks. ServiceNow describes CVE-2026-6876 as an issue that could allow an unauthenticated user to execute arbitrary code within the Now Platform, with low privileges required.
