The KB3152242 Disclosure

ServiceNow published advisory KB3152242 on August 27, disclosing three unauthenticated, zero-interaction vulnerabilities in ServiceNow AI Platform, each carrying the maximum CVSS 10.0 severity score. None of the flaws requires credentials or user interaction, and all are remotely exploitable in default configurations. The cluster follows the July CVE-2026-6875 advisory, the second critical ServiceNow AI Platform advisory in roughly five weeks.
Three CVEs at Maximum Severity
The advisory identifies CVE-2026-18885, a code injection flaw that lets an unauthenticated attacker execute arbitrary code on a ServiceNow AI Platform instance, with a CVSS vector indicating network-adjacent reachability, low attack complexity and no privileges required. CVE-2026-18886 is an access control bypass that lets an unauthenticated requester invoke functionality meant for elevated privileges, exposing the ability to trigger actions rather than only data. CVE-2026-74820 is a SQL injection vulnerability that gives an attacker direct access to the backing database.
Why the AI Layer Changes the Risk
Unlike code injection in a conventional web application, the platform holds session context, tool configurations and credentials that AI agents use to act on behalf of users. The SQL injection vector similarly reaches beyond application data to conversation histories, tool configurations, authentication tokens cached for agent use, and the knowledge base content agents rely on for decision-making. The reporting frames this as an architectural question about how deeply agents inherit the security posture of the platforms they connect to.
The Agent Amplification Effect
The disclosure is distinguished from the earlier CVE-2026-6875 pre-authenticated remote code execution flaw by targeting the AI layer that sits on top of ServiceNow instances rather than the instances themselves. Organizations typically grant AI agents broad access to read and write records, trigger workflows, escalate tickets, query connected data sources and, in some configurations, execute scripts, so a compromised platform effectively compromises the agent without separate effort. The reporting cites the Langflow CVE-2026-55255 chain in July and the MCP stateless shift as prior examples of the same dynamic, in which removing server-side session state turns every request into a potential injection point.
Open Questions and Patch Timeline
The August 27 advisory does not disclose the specific injection points behind CVE-2026-18885, and the reporting does not state a ServiceNow patch release date or mitigation guidance beyond framing the issue as a patching exercise for affected organizations. No ServiceNow statement, customer impact tally, or exploitation-in-the-wild evidence appears in the source set, leaving the operational response timeline unresolved in the available reporting.
Share this article







