Incorrect authorization in ServiceNow - CVE-2026-86857
Published: September 25, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to an authorization bypass in the ServiceNow AI Platform when handling requests. A remote user can access data beyond their intended authorization to disclose sensitive information.
Exploitation may enable further unintended access.