Three CVSS 10.0 ServiceNow Flaws Could Let Unauthenticated Attackers Execute Code and SQL

A trio of critical vulnerabilities in ServiceNow, a leading IT service management platform, has left thousands of organizations vulnerable to unauthenticated attacks. The three flaws, each rated CVSS 10.0, allow attackers to execute code and manipulate SQL databases without needing credentials. This is a serious concern for companies that rely on ServiceNow to manage their internal operations.

The vulnerabilities, discovered in the platform’s web application, are related to authentication bypass and privilege escalation. In simpler terms, this means that an attacker can exploit these flaws to gain access to sensitive areas of the system and execute malicious code without needing proper authorization. This is particularly worrying because it allows attackers to move freely within a network, potentially leading to more severe consequences.

ServiceNow’s platform is widely used by large enterprises, governments, and other organizations worldwide. According to the company’s own estimates, over 20,000 businesses rely on their services. While ServiceNow has taken steps to address these vulnerabilities, it is unclear how many organizations have already been affected. It’s also uncertain whether all of them are aware of the issue.

The root cause of this problem lies in the way ServiceNow handles authentication and authorization. The platform uses a combination of techniques to grant users access to different areas based on their roles and permissions. However, it appears that these checks can be bypassed using the discovered vulnerabilities. This allows attackers to escalate privileges and execute code without needing proper credentials.

The fact that these flaws have been rated CVSS 10.0, the highest rating possible, indicates just how severe they are. This is not a matter of “could” or “might,” but rather a certainty – if an attacker exploits these vulnerabilities, it will lead to serious consequences for affected organizations. In this case, the consequences could be catastrophic, ranging from data breaches to full-blown network takeovers.

To mitigate these risks, organizations should take immediate action. This includes patching their ServiceNow installations with the latest security updates and reviewing user permissions to ensure that access controls are properly configured. It’s also essential for companies to monitor their networks closely for any suspicious activity that might indicate an attack has been launched using these vulnerabilities.


Source: The Hacker News — 2026-08-28