Description
ServiceNow has remediated a missing authorization vulnerability that was identified in the ServiceNow AI Platform. This vulnerability could enable an unauthenticated user, in certain circumstances, to extract instance data beyond what was intended, resulting in privilege escalation.





ServiceNow deployed a security update to hosted instances and ServiceNow provided the update to our partners and self-hosted customers. We are not currently aware of malicious exploitation against ServiceNow instances. We recommend customers promptly apply appropriate updates or upgrade to a patched release if they have not already done so.
Published: 2026-09-24
Score: 9.3 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Unauthenticated sensitive data disclosure
Action: Immediate patch
AI Analysis

Impact

The vulnerability is a missing authorization flaw in the ServiceNow AI Platform that permits unauthenticated users to read data beyond the intended scope, potentially exposing sensitive information and enabling privilege escalation.

Affected Systems

Affected systems include all instances of the ServiceNow AI Platform distributed by ServiceNow, encompassing both hosted environments provided by the vendor and self‑hosted deployments managed by customers. No specific version numbers are listed in the advisory, so any instance running the AI Platform is considered at risk until the update is applied.

Risk and Exploitability

With a CVSS score of 9.3 the flaw is classified as high severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. The attack vector appears to be unauthenticated remote access to the platform, and no malicious exploitation has been reported. Prompt application of the vendor’s patch is the recommended mitigation to prevent data exposure.

Generated by OpenCVE AI on September 25, 2026 at 03:54 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the vendor‑released security update for ServiceNow AI Platform.
  • Deploy the patch to all hosted and self‑hosted instances, including partner‑managed environments.
  • Review AI Platform access logs and configuration files for any remaining unauthorized data access patterns and enforce stricter role‑based access controls.

Generated by OpenCVE AI on September 25, 2026 at 03:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 25 Sep 2026 06:30:00 +0000

Type Values Removed Values Added
First Time appeared Servicenow
Servicenow servicenow Ai Platform
Vendors & Products Servicenow
Servicenow servicenow Ai Platform

Thu, 24 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-862
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 24 Sep 2026 19:15:00 +0000

Type Values Removed Values Added
Description ServiceNow has remediated a missing authorization vulnerability that was identified in the ServiceNow AI Platform. This vulnerability could enable an unauthenticated user, in certain circumstances, to extract instance data beyond what was intended, resulting in privilege escalation. ServiceNow deployed a security update to hosted instances and ServiceNow provided the update to our partners and self-hosted customers. We are not currently aware of malicious exploitation against ServiceNow instances. We recommend customers promptly apply appropriate updates or upgrade to a patched release if they have not already done so.
Title Unauthenticated Sensitive Data Disclosure in ServiceNow AI Platform
References
Metrics cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:N'}


Subscriptions

Servicenow Servicenow Ai Platform
cve-icon MITRE

Status: PUBLISHED

Assigner: SN

Published:

Updated: 2026-09-25T03:55:29.102Z

Reserved: 2026-09-08T15:46:52.557Z

Link: CVE-2026-86860

cve-icon Vulnrichment

Updated: 2026-09-24T19:11:48.410Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-24T19:17:18.733

Modified: 2026-09-25T04:17:48.557

Link: CVE-2026-86860

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-25T06:15:16Z

Weaknesses