Impact
ServiceNow has identified an authorization bypass flaw in its AI Platform. A non‑authenticated attacker can retrieve records that the system normally protects, leading to the disclosure of confidential information. The vulnerability arises from improper enforcement of access control, as indicated by CWEs associated with access control failures, and can fully compromise data confidentiality for affected systems.
Affected Systems
The vulnerability affects ServiceNow AI Platform instances, including both hosted and self‑hosted deployments. Specific version information is not disclosed in the available data, so all current releases should be examined for the applied security fix.
Risk and Exploitability
With a CVSS score of 8.7, this issue poses a high risk. The EPSS score is not available, and it is not listed in the CISA KEV catalog, suggesting no confirmed exploitation yet. The likely attack vector is remote, via unauthenticated requests to the AI Platform’s interfaces, which can be performed over the internet or internal networks. Any successful exploitation would grant an attacker access to data beyond their authorization.
OpenCVE Enrichment