THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-18886 — ServiceNow has remediated an improper access control vulnerability that was identified in the ServiceNow AI platform. This vulnerability could enable an unauthenticated user, in certain circumstances, to create or modify instance data beyond what was intended, resulting in privil

[NVD] CVE-2026-18886 — ServiceNow has remediated an improper access control vulnerability that was identified in the ServiceNow AI platform. This vulnerability could enable an unauthenticated user, in certain circumstances, to create or modify instance data beyond what was intended, resulting in privil

mednvdPublished 2026-08-27

CVE-2026-18886 CVSS: None Published: 2026-08-27T20:17:04.020

ServiceNow has remediated an improper access control vulnerability that was identified in the ServiceNow AI platform. This vulnerability could enable an unauthenticated user, in certain circumstances, to create or modify instance data beyond what was intended, resulting in privilege escalation. 

ServiceNow deployed a security upda

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-18886