Impact
The vulnerability is a missing authorization flaw in the ServiceNow AI Platform that permits unauthenticated users to read data beyond the intended scope, potentially exposing sensitive information and enabling privilege escalation.
Affected Systems
Affected systems include all instances of the ServiceNow AI Platform distributed by ServiceNow, encompassing both hosted environments provided by the vendor and self‑hosted deployments managed by customers. No specific version numbers are listed in the advisory, so any instance running the AI Platform is considered at risk until the update is applied.
Risk and Exploitability
With a CVSS score of 9.3 the flaw is classified as high severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. The attack vector appears to be unauthenticated remote access to the platform, and no malicious exploitation has been reported. Prompt application of the vendor’s patch is the recommended mitigation to prevent data exposure.
OpenCVE Enrichment