Incorrect authorization in ServiceNow - CVE-2026-86859
Published: September 25, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to an authorization bypass in the ServiceNow AI Platform when handling requests. A remote attacker can access data beyond intended authorization to disclose sensitive information.
Exploitation may enable further unintended access.