SB20260925256 - Multiple vulnerabilities in ServiceNow AI Platform



SB20260925256 - Multiple vulnerabilities in ServiceNow AI Platform

Published: September 25, 2026

Security Bulletin ID SB20260925256
CSH Severity
Medium
Patch available
YES
Number of vulnerabilities 5
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Medium 60% Low 40%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 5 vulnerabilities.


1) Incorrect authorization (CVE-ID: CVE-2026-86857)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to an authorization bypass in the ServiceNow AI Platform when handling requests. A remote user can access data beyond their intended authorization to disclose sensitive information.

Exploitation may enable further unintended access.


2) Improper access control (CVE-ID: CVE-2026-86858)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: 8.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to create, modify, or delete instance data.

The vulnerability exists due to improper access control in the ServiceNow AI Platform when handling requests. A remote attacker can create, modify, or delete instance data beyond intended access controls to create, modify, or delete instance data.

Exploitation is possible only in certain circumstances.


3) SQL injection (CVE-ID: CVE-2026-13016)

CWE-ID: CWE-89 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

CVSSv4: 9.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary SQL statements and access or modify instance data.

The vulnerability exists due to SQL injection in the ServiceNow AI Platform when processing user-supplied input. A remote attacker can submit crafted SQL input to execute arbitrary SQL statements and access or modify instance data.

Exploitation is possible only in certain circumstances.


4) Incorrect authorization (CVE-ID: CVE-2026-86859)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to an authorization bypass in the ServiceNow AI Platform when handling requests. A remote attacker can access data beyond intended authorization to disclose sensitive information.

Exploitation may enable further unintended access.


5) Missing Authorization (CVE-ID: CVE-2026-86860)

CWE-ID: CWE-862 - Missing Authorization

CVSSv4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to extract instance data and escalate privileges.

The vulnerability exists due to missing authorization in the ServiceNow AI Platform when handling requests. A remote attacker can extract instance data beyond intended authorization to extract instance data and escalate privileges.

Exploitation is possible only in certain circumstances.


Remediation

Install update from vendor's website.