Three times 10 out of 10. ServiceNow has closed holes through which you can get to corporate data without a password

Depov

Moderator
Staff member
MODERATOR
ULTIMATE
SUPREME
PREMIUM
MEMBER
Joined
Feb 18, 2025
Messages
443
Reaction score
723
Deposit
0$
ServiceNow has closed three vulnerabilities of maximum criticality in the AI Platform. Each received 10 points out of 10 on the CVSS 4.0 scale, and no account or user action is needed for a potential attack. In a worst-case scenario, an attacker can execute arbitrary code or SQL teams and access corporate data.

The most dangerous looks CVE-2026-18885 in the GraphQL Composite Data API. The error allows you to implement the code and, under certain conditions, execute it on the platform without prior authentication. A successful attack can give access to the data of the copy of ServiceNow and allow you to change the information to which the attacker should not have access.

The second vulnerability of CVE-2026-18886 is due to insufficient access control when booting system configuration images. An unauthorized user under certain conditions can create or modify data inside the ServiceNow instance and increase their privileges.

CVE-2026-74820 is a SQL injection in the dynamic circuit processing mechanism. The vulnerability allows you to send arbitrary SQL commands to the platform database without authorization. As a result, the attacker is potentially able to read or modify corporate information.


ServiceNow has already installed corrections on the platform instances placed in its own cloud and has passed updates to partners and customers who deploy ServiceNow on their own. Owners of local installations need to install the corrected versions themselves. Vulnerabilities affect a number of issues of Xanadu, Yokohama, Zurich and Australia. The Canadian Cyber Security Center on August 28 separately warned ServiceNow administrators and recommended installing available updates.

According to ServiceNow, signs of real attacks through three new vulnerabilities have not yet been detected. As of August 28, public exploits were also not found for them. However, the maximum CVSS score is not only related to possible damage. All three issues are available over the network, have low complexity of operation and require neither privileges nor user interaction.

The potential consequences are particularly serious because of ServiceNow’s role in large organizations. The platform serves IT processes, infrastructure and asset management, workflow automation and information security operations. Compromising such a node can give the attacker access not to a separate application, but to data and processes related to several parts of the corporate infrastructure.
 
Top Bottom