Impact
An improper access control flaw in the image upload processor of ServiceNow AI Platform allows an unauthenticated user to create or alter instance data beyond the intended scope, effectively escalating privileges. The vulnerability is restricted to scenarios where unauthenticated access paths are available for image uploads; otherwise, the risk is mitigated. No exploitation has been reported yet, but the potential for significant data tampering or damage exists.
Affected Systems
The flaw affects ServiceNow AI Platform, including both hosted instances and self-hosted deployments. No specific version numbers are listed, so all current releases should be evaluated for the presence of the issue.
Risk and Exploitability
The CVSS score of 10 rates this vulnerability as Critical, reflecting the combination of unauthenticated access and the ability to modify system data. EPSS data is unavailable, so the current exploit probability cannot be quantified, but the lack of known exploitation coupled with the high CVSS suggests that operators should treat this as a high‑risk scenario. The vulnerability is not listed in the CISA KEV catalog, which indicates that, as of this writing, there have been no confirmed attacks, yet the attack vector—unauthenticated image upload—remains exploitable.
OpenCVE Enrichment