{
  "id": 4750749,
  "title": "Unauthenticated RCE, Privilege Escalation, and SQL Injection in ServiceNow AI Platform: Three CVSS 10.0 Vulnerabilities",
  "url": "https://urgent.news/2026/09/01/unauthenticated-rce-privilege-escalation-and-sql-injection-in",
  "topic": "ai",
  "section": "AI",
  "published": "2026-09-01T00:36:37.000Z",
  "source": {
    "name": "Dev.to",
    "slug": "dev-to",
    "url": "https://dev.to/anoymask/unauthenticated-rce-privilege-escalation-and-sql-injection-in-servicenow-ai-platform-three-cvss-3g40"
  },
  "original_language": "en",
  "account": "ServiceNow has released patches for three critical code injection vulnerabilities, an access control flaw, and SQL injection in their AI Platform. The vulnerabilities, listed as CVE-2026-18885, CVE-2026-18886, CVE-2026-74820, and CVE-2026-6876, could allow an attacker to execute arbitrary code, manipulate data, escalate privileges, and compromise the underlying database. These flaws were exploitable remotely without authentication, highlighting the urgency of the service provider's response.",
  "summary": "1. Basic Information Article Title : ServiceNow Patches 3 Critical Code Injection Vulnerabilities Source : SecurityWeek Publication Date : 2026-08-31 Original Article : SecurityWeek Related Sources : ServiceNow August 2026 CVE Advisory , BleepingComputer Related Malware, Threat Groups, CVEs, Products : CVE-2026-18885, CVE-2026-18886, CVE-2026-74820, CVE-2026-6876, ServiceNow AI Platform, Now…",
  "key_points": [
    "Three critical vulnerabilities discovered in ServiceNow AI Platform",
    "Remote exploitation possible without authentication",
    "CVSS 10.0 rating assigned to all vulnerabilities"
  ],
  "editors_take": "The release of patches by ServiceNow underscores the severity of code injection risks in AI platforms, particularly when exploitable remotely without authentication, and highlights the need for swift vendor response to vulnerability disclosures.",
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}