SQL injection in ServiceNow - CVE-2026-13016

 

SQL injection in ServiceNow - CVE-2026-13016

Published: September 25, 2026


Vulnerability identifier: #VU152243
CSH Severity: Medium
CVSS v4: 9.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-13016
CWE-ID: CWE-89
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary SQL statements and access or modify instance data.

The vulnerability exists due to SQL injection in the ServiceNow AI Platform when processing user-supplied input. A remote attacker can submit crafted SQL input to execute arbitrary SQL statements and access or modify instance data.

Exploitation is possible only in certain circumstances.


Affected software

ServiceNow

How to mitigate CVE-2026-13016

Install security update from vendor's website.

ServiceNow - addressed in versions Australia Patch 2 Hot Fix 4b W32, Australia Patch 4 Hot Fix 3, Australia Patch 5, Yokohama Patch 13 Hot Fix 5a, Zurich Patch 10 Hot Fix 3b, Zurich Patch 10 Hot Fix 4a W32, Zurich Patch 11 Hot Fix 3

External References

Related Security Bulletins