Advertisement

ServiceNow patches five AI Platform security flaws

ServiceNow has disclosed five security vulnerabilities in its AI Platform, including two critical weaknesses that could let unauthenticated attackers reach sensitive instance data, alter database content or escalate privileges.

The flaws were published on September 24 under ServiceNow advisory KB3159623 and are tracked as CVE-2026-86857, CVE-2026-86858, CVE-2026-13016, CVE-2026-86859 and CVE-2026-86860. ServiceNow said the issues had been remediated independently and that it had found no evidence of malicious exploitation against customer instances.

The most severe issues are CVE-2026-13016 and CVE-2026-86860, both rated critical with CVSS 4.0 scores of 9.3. CVE-2026-13016 is an SQL injection vulnerability that can, under certain circumstances, allow an unauthenticated attacker to execute arbitrary SQL statements against the underlying database. Successful exploitation could expose or modify instance data beyond the access intended by the platform.

CVE-2026-86860 is a missing-authorisation weakness that can permit an unauthenticated user to extract instance data outside normal access controls. ServiceNow said exploitation could result in privilege escalation, making the flaw significant for organisations that use the platform to handle business workflows and sensitive operational records.

Three additional vulnerabilities carry high-severity ratings. CVE-2026-86858, scored 8.7 under CVSS 4.0, is an improper access-control issue affecting the platform’s GraphQL functionality. It could allow an unauthenticated attacker to create, modify or delete instance data beyond authorised limits. ServiceNow said a security update addressing this issue was deployed to hosted instances in August.

CVE-2026-86859, also rated 8.7, is an authorisation-bypass flaw that could enable an unauthenticated user to access data that should otherwise be restricted. The vulnerability could lead to further unintended access, although the company has not reported attacks exploiting it.

CVE-2026-86857 has a CVSS 4.0 score of 8.4 and differs from the other newly disclosed issues because exploitation requires an authenticated user with low privileges. The authorisation-bypass weakness could permit that user to reach information outside their assigned permissions and potentially obtain broader unintended access.

ServiceNow said the five flaws were identified through internal security testing, customer security assessments or submissions made through its responsible-disclosure and bug-bounty programmes. The company said hosted environments had received the relevant fixes, while updates were supplied to partners and customers operating self-hosted deployments.

Official vulnerability records list affected ServiceNow AI Platform builds as versions earlier than Yokohama Patch 13 Hot Fix 5a, Zurich Patch 10 Hot Fix 3b, Zurich Patch 10 Hot Fix 4a W32, Zurich Patch 11 Hot Fix 3, Australia Patch 2 Hot Fix 4b W32, Australia Patch 4 Hot Fix 3 and Australia Patch 5. Customers running older releases have been urged to install the appropriate update or move to a patched version.

The disclosure follows a separate set of ServiceNow AI Platform fixes announced in August for three maximum-severity vulnerabilities and a high-severity sandbox escape. Those earlier defects included code-injection, privilege-escalation and SQL-injection weaknesses, showing that access-control and input-validation problems remain important areas for administrators maintaining exposed enterprise instances.

ServiceNow’s September advisory does not identify active exploitation of the five newly published CVEs. CISA’s vulnerability enrichment data likewise recorded no exploitation for the issues when the entries were published, although several were classified as automatable, meaning exploitation may not require extensive manual interaction once a working technique is developed.

The critical SQL injection entry is classified as network-accessible, low-complexity and requiring neither privileges nor user interaction. The critical missing-authorisation flaw carries the same network, complexity and authentication characteristics. The two 8.7-rated unauthenticated access-control defects are also network reachable without user interaction, while CVE-2026-86857 requires low privileges. These characteristics increase the importance of identifying externally reachable instances and confirming that security updates have been applied consistently across production, test, disaster-recovery and other replicated systems where applicable.

The company’s guidance focuses on patching rather than temporary mitigations. Administrators of self-hosted instances therefore need to compare their deployed family and patch level with the affected-version ranges, apply the corresponding hot fixes and verify that systems have reached a release containing the security corrections.
Previous Post Next Post

Advertisement

Advertisement

نموذج الاتصال