Impact
The vulnerability is an improper access control flaw that allows an unauthenticated user to create, modify, or delete instance data beyond what is allowed by design. This can lead to unauthorized data manipulation or loss of integrity in the ServiceNow AI Platform. The flaw is tied to CWE‑284, indicating weaknesses in access control enforcement.
Affected Systems
The affected product is ServiceNow AI Platform. No specific version details are provided, but the August 2026 update addresses the issue.
Risk and Exploitability
The CVSS score of 8.7 signifies a high severity risk. EPSS is not available, and the vulnerability is not listed in CISA KEV. The likelihood of exploitation is uncertain, but given the unauthenticated nature of the flaw, a potential attacker could exploit the GraphQL interface if it remains accessible without proper authentication checks. No additional prerequisites are noted beyond an unauthenticated request to the GraphQL endpoint.
OpenCVE Enrichment