ServiceNow Reports Critical Security Vulnerabilities in AI Platform
ServiceNow has recently announced the discovery of five significant vulnerabilities within its AI Platform, which has raised concerns regarding the potential security implications for users. Among these vulnerabilities, two have been classified as critical, presenting a serious risk that could enable unauthenticated attackers to execute arbitrary SQL commands, extract sensitive instance data, modify records, and escalate their privileges.
In a security advisory published on September 24, 2026, and cataloged as KB3159623, ServiceNow detailed the vulnerabilities tracked under the identifiers CVE-2026-86857, CVE-2026-86858, CVE-2026-13016, CVE-2026-86859, and CVE-2026-86860. Importantly, the company stated that, thus far, it has found no evidence indicating that these vulnerabilities have been exploited maliciously in live environments.
Critical SQL Injection Vulnerability
The most alarming of the reported issues, CVE-2026-13016, has been identified as a critical SQL injection vulnerability. This flaw could allow an unauthenticated attacker to execute arbitrary SQL statements against the underlying database of an affected instance under specific circumstances. Successful exploitation of this vulnerability can lead to unauthorized access or alteration of instance data, which could ultimately expose sensitive enterprise records stored within the ServiceNow platform.
The types of data potentially at risk include IT service management tickets, asset data, HR-related information, workflow records, configuration data, and other critical business content. The extent of the exposure varies depending on how an organization utilizes the platform.
ServiceNow has assessed this critical vulnerability using the CVSS v4.0 calculator, ultimately categorizing it as a significant security risk, internally tracked under PRB2036897.
Additional Critical Vulnerability
Another critical vulnerability noted in the advisory is CVE-2026-86860, which stems from missing authorization controls. This flaw could enable unauthenticated attackers to extract information from a vulnerable ServiceNow instance beyond what was intended, which could facilitate privilege escalation. Internally, this issue is tracked as PRB2050429.
High-Severity Access Control Vulnerabilities
In addition to the critical weaknesses, the security advisory enumerates three high-severity vulnerabilities related to authorization and access control. These vulnerabilities open up paths for abuse within the platform:
-
CVE-2026-86857: This high-severity vulnerability involves an authorization bypass, allowing authenticated users to access AI Platform data that they are not authorized to view.
-
CVE-2026-86858: Significant in its impact, this vulnerability allows unauthenticated attackers the ability to create, modify, or delete instance data. This could lead to integrity attacks affecting business workflows, incident records, change management entries, or other vital data within the affected deployment.
- CVE-2026-86859: Similar to CVE-2026-86857, this authorization bypass vulnerability permits unauthenticated attackers access to restricted AI Platform data.
The nature of these flaws highlights an urgent need for organizations to take immediate action to mitigate the potential for security breaches.
Discovery and Remediation Efforts
ServiceNow has identified these vulnerabilities through various means, including internal testing and customer security assessments, as well as through responsible disclosure submissions and its bug bounty program. Each vulnerability was addressed and remediated independently, aiming to safeguard user data effectively.
Regaining Control: Patched Releases
For organizations already enrolled in ServiceNow’s August Patching Program, updates addressing these vulnerabilities have already been distributed. Self-hosted customers are urged to promptly apply available fixes or upgrade to patched releases. The following versions include the necessary security updates from September 2026:
- Yokohama: Patch 13 Hot Fix 5a
- Zurich: Patch 10 Hot Fix 4a W32
- Australia: Patch 2 Hot Fix 4b W32
- Zurich: Patch 10 Hot Fix 3b or Patch 11 Hot Fix 3
- Australia: Patch 4 Hot Fix 3 or Patch 5
Organizations running self-hosted ServiceNow AI Platform instances are advised to check their respective release and patch levels and upgrade to secure versions promptly.
Furthermore, security teams should conduct thorough reviews of instance access logs, administrative activities, abnormal record modifications, and any unusual database-related errors to detect signs of attempted exploitation. Due to the potential infiltration methods enabled by the critical SQL injection flaw and other vulnerabilities, prioritizing these updates is essential, especially where ServiceNow instances manage sensitive operational, customer, employee, or security workflow data.
In summary, ServiceNow has taken proactive steps to improve the security of its AI Platform, urging its clients to act quickly in mitigating risks associated with these vulnerabilities. The overall security landscape necessitates vigilance and immediate action in response to identified risks to ensure user data remains protected.

