CVE-2026-86859

8.7

ServiceNow · ServiceNow AI Platform

An authorization bypass in the ServiceNow AI Platform allows unauthenticated attackers to access restricted data, potentially leading to further unauthorized system access.

Executive summary

An authorization bypass vulnerability in the ServiceNow AI Platform allows unauthenticated attackers to gain unauthorized access to sensitive data, posing a high risk to organizational information security.

Vulnerability

This is an authorization bypass vulnerability affecting the AI Platform component. It permits an unauthenticated user to access data they are not permitted to view, which may facilitate broader unauthorized access.

Business impact

The vulnerability carries a CVSS score of 8.7, indicating a high level of severity. Successful exploitation could lead to the exposure of sensitive corporate or customer data stored within the AI platform, resulting in severe reputational damage, compliance violations, and potential legal consequences.

Remediation

Immediate Action: Upgrade your ServiceNow instance to the specified patched release or apply the appropriate hotfix as provided in KB3159623 immediately.

Proactive Monitoring: Review system access logs for anomalous patterns, specifically looking for unauthorized data requests originating from unauthenticated sessions or unexpected service accounts.

Compensating Controls: Implement strict network segmentation and ensure that the AI platform is not exposed to the public internet unless absolutely necessary, utilizing a Web Application Firewall to filter suspicious traffic.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the high severity score and the ability for unauthenticated attackers to bypass security controls, this vulnerability requires immediate attention. Administrators should prioritize patching their ServiceNow AI Platform instances to the versions listed above to prevent potential data exfiltration and unauthorized access.

More ServiceNow CVEs

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief high section

Sources