SB20260925256 - Multiple vulnerabilities in ServiceNow AI Platform
Published: September 25, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 5 vulnerabilities.
1) Incorrect authorization (CVE-ID: CVE-2026-86857)
CWE-ID: CWE-863 - Incorrect Authorization
CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to an authorization bypass in the ServiceNow AI Platform when handling requests. A remote user can access data beyond their intended authorization to disclose sensitive information.
Exploitation may enable further unintended access.
2) Improper access control (CVE-ID: CVE-2026-86858)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 8.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to create, modify, or delete instance data.
The vulnerability exists due to improper access control in the ServiceNow AI Platform when handling requests. A remote attacker can create, modify, or delete instance data beyond intended access controls to create, modify, or delete instance data.
Exploitation is possible only in certain circumstances.
3) SQL injection (CVE-ID: CVE-2026-13016)
CWE-ID: CWE-89 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVSSv4: 9.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary SQL statements and access or modify instance data.
The vulnerability exists due to SQL injection in the ServiceNow AI Platform when processing user-supplied input. A remote attacker can submit crafted SQL input to execute arbitrary SQL statements and access or modify instance data.
Exploitation is possible only in certain circumstances.
4) Incorrect authorization (CVE-ID: CVE-2026-86859)
CWE-ID: CWE-863 - Incorrect Authorization
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to an authorization bypass in the ServiceNow AI Platform when handling requests. A remote attacker can access data beyond intended authorization to disclose sensitive information.
Exploitation may enable further unintended access.
5) Missing Authorization (CVE-ID: CVE-2026-86860)
CWE-ID: CWE-862 - Missing Authorization
CVSSv4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to extract instance data and escalate privileges.
The vulnerability exists due to missing authorization in the ServiceNow AI Platform when handling requests. A remote attacker can extract instance data beyond intended authorization to extract instance data and escalate privileges.
Exploitation is possible only in certain circumstances.
Remediation
Install update from vendor's website.