SQL injection in ServiceNow - CVE-2026-13016
Published: September 25, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary SQL statements and access or modify instance data.
The vulnerability exists due to SQL injection in the ServiceNow AI Platform when processing user-supplied input. A remote attacker can submit crafted SQL input to execute arbitrary SQL statements and access or modify instance data.
Exploitation is possible only in certain circumstances.