Missing Authorization in ServiceNow - CVE-2026-86860
Published: September 25, 2026
Vulnerability details
The vulnerability allows a remote attacker to extract instance data and escalate privileges.
The vulnerability exists due to missing authorization in the ServiceNow AI Platform when handling requests. A remote attacker can extract instance data beyond intended authorization to extract instance data and escalate privileges.
Exploitation is possible only in certain circumstances.