CVE-2026-86860

9.3

ServiceNow · ServiceNow AI Platform

A missing authorization flaw in the ServiceNow AI Platform allows unauthenticated users to perform unauthorized data extraction and privilege escalation.

Executive summary

A critical authorization bypass vulnerability in the ServiceNow AI Platform poses a severe risk of unauthorized data extraction and privilege escalation by unauthenticated attackers.

Vulnerability

This is a missing authorization vulnerability where the system fails to perform necessary access control checks on the AI Platform. An unauthenticated attacker can leverage this flaw to access sensitive instance data and escalate privileges within the application environment.

Business impact

The exploitation of this vulnerability could lead to the unauthorized disclosure of sensitive organizational data, potentially resulting in significant regulatory and reputational harm. Given the CVSS score of 9.3, the vulnerability is classified as critical because it allows for full data confidentiality impact and systemic privilege escalation without requiring any user interaction or prior authentication.

Remediation

Immediate Action: Administrators must immediately apply the relevant security patches provided by ServiceNow for their specific instance version as detailed in KB3159623.

Proactive Monitoring: Security teams should review system access logs for anomalous, unauthenticated requests targeting the AI Platform and monitor for unexpected increases in data export activities.

Compensating Controls: Deploy Web Application Firewall (WAF) rules designed to detect and block unauthorized API requests or suspicious patterns targeting the AI Platform endpoints until patches are fully deployed.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Due to the critical severity and the potential for total impact on data confidentiality, organizations must prioritize the application of the vendor-supplied patches. Failure to remediate this vulnerability leaves the instance exposed to unauthenticated actors who could gain unauthorized access to sensitive information and elevate their privileges within the ServiceNow environment.

More ServiceNow CVEs

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief critical section

Sources