Description
ServiceNow has remediated an improper access control vulnerability that was identified in the ServiceNow AI platform. This vulnerability could enable an unauthenticated user, in certain circumstances, to create or modify instance data beyond what was intended, resulting in privilege escalation. 





ServiceNow deployed a security update to hosted instances and ServiceNow provided the update to our partners and self-hosted customers. We are not currently aware of exploitation against ServiceNow instances. 



We recommend customers promptly apply appropriate updates or upgrade to a patched release if they have not already done so.
Published: 2026-08-27
Score: 10 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An improper access control flaw in the image upload processor of ServiceNow AI Platform allows an unauthenticated user to create or alter instance data beyond the intended scope, effectively escalating privileges. The vulnerability is restricted to scenarios where unauthenticated access paths are available for image uploads; otherwise, the risk is mitigated. No exploitation has been reported yet, but the potential for significant data tampering or damage exists.

Affected Systems

The flaw affects ServiceNow AI Platform, including both hosted instances and self-hosted deployments. No specific version numbers are listed, so all current releases should be evaluated for the presence of the issue.

Risk and Exploitability

The CVSS score of 10 rates this vulnerability as Critical, reflecting the combination of unauthenticated access and the ability to modify system data. EPSS data is unavailable, so the current exploit probability cannot be quantified, but the lack of known exploitation coupled with the high CVSS suggests that operators should treat this as a high‑risk scenario. The vulnerability is not listed in the CISA KEV catalog, which indicates that, as of this writing, there have been no confirmed attacks, yet the attack vector—unauthenticated image upload—remains exploitable.

Generated by OpenCVE AI on August 28, 2026 at 05:41 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the ServiceNow security update released for the AI Platform as soon as possible.
  • If the update is not yet available, upgrade to a patched release that incorporates the fix for image upload access control.
  • Disable or restrict image upload functionality for unauthenticated users until the mitigation is in place.

Generated by OpenCVE AI on August 28, 2026 at 05:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 28 Aug 2026 06:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-862

Thu, 27 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Description ServiceNow has remediated an improper access control vulnerability that was identified in the ServiceNow AI platform. This vulnerability could enable an unauthenticated user, in certain circumstances, to create or modify instance data beyond what was intended, resulting in privilege escalation.  ServiceNow deployed a security update to hosted instances and ServiceNow provided the update to our partners and self-hosted customers. We are not currently aware of exploitation against ServiceNow instances.  We recommend customers promptly apply appropriate updates or upgrade to a patched release if they have not already done so.
Title Unauthenticated Privilege Escalation via System Configuration Image Upload Processor
References
Metrics cvssV4_0

{'score': 10, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: SN

Published:

Updated: 2026-08-27T19:00:01.715Z

Reserved: 2026-08-04T19:02:05.799Z

Link: CVE-2026-18886

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-27T20:17:04.020

Modified: 2026-08-27T20:17:04.020

Link: CVE-2026-18886

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-28T05:45:04Z

Weaknesses