Improper access control in ServiceNow - CVE-2026-86858

 

Improper access control in ServiceNow - CVE-2026-86858

Published: September 25, 2026


Vulnerability identifier: #VU152242
CSH Severity: Medium
CVSS v4: 8.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-86858
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to create, modify, or delete instance data.

The vulnerability exists due to improper access control in the ServiceNow AI Platform when handling requests. A remote attacker can create, modify, or delete instance data beyond intended access controls to create, modify, or delete instance data.

Exploitation is possible only in certain circumstances.


Affected software

ServiceNow

How to mitigate CVE-2026-86858

Install security update from vendor's website.

ServiceNow - addressed in versions Australia Patch 2 Hot Fix 4b W32, Australia Patch 4 Hot Fix 3, Australia Patch 5, Yokohama Patch 13 Hot Fix 5a, Zurich Patch 10 Hot Fix 3b, Zurich Patch 10 Hot Fix 4a W32, Zurich Patch 11 Hot Fix 3

External References

Related Security Bulletins