CVE-2026-74820: how an unsanitized ORDER BY clause turned ServiceNow's AI Platform into an unauthenticated database backdoor
Inside CVE-2026-74820: a CVSS 10.0 unauthenticated SQL injection in ServiceNow's AI Platform, reachable through a dynamic schema ORDER BY cl...