Vulnerability identifier: #VU152242
CSH Severity: Medium
CVSS v4: 8.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-86858
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to create, modify, or delete instance data.
The vulnerability exists due to improper access control in the ServiceNow AI Platform when handling requests. A remote attacker can create, modify, or delete instance data beyond intended access controls to create, modify, or delete instance data.
Exploitation is possible only in certain circumstances.
Affected software
ServiceNow
How to mitigate CVE-2026-86858
Install security update from vendor's website.
ServiceNow - addressed in versions Australia Patch 2 Hot Fix 4b W32, Australia Patch 4 Hot Fix 3, Australia Patch 5, Yokohama Patch 13 Hot Fix 5a, Zurich Patch 10 Hot Fix 3b, Zurich Patch 10 Hot Fix 4a W32, Zurich Patch 11 Hot Fix 3
External References
Related Security Bulletins