CVE-2026-74820
Severity CVSS v4.0:
CRITICAL
Type:
CWE-89
SQL Injection
Publication date:
27/08/2026
Last modified:
29/08/2026
Description
ServiceNow has remediated a SQL injection vulnerability that was identified in in the ServiceNow AI platform. This vulnerability could enable an unauthenticated user, in certain circumstances, to execute arbitrary SQL statements against the instance&#39;s underlying database and gain access to, or modify, instance data beyond what was intended. <br />
<br />
<br />
<br />
<br />
<br />
ServiceNow deployed a security update to hosted instances and ServiceNow provided the update to our partners and self-hosted customers. We are not currently aware of malicious exploitation against ServiceNow instances. <br />
<br />
<br />
<br />
We recommend customers promptly apply appropriate updates or upgrade to a patched release if they have not already done so.
Impact
Base Score 4.0
10.00
Severity 4.0
CRITICAL



