Skip to content
ServiceNow AI Platform Fixes Two Critical Flaws Open to Unauthenticated Attackers

ServiceNow AI Platform Fixes Two Critical Flaws Open to Unauthenticated Attackers

Kobaran • September 26, 2026

ServiceNow has patched five security vulnerabilities in its AI Platform. Two of them are rated critical and could let attackers read, change, or delete data on affected instances without ever logging in. The company detailed the fixes in security advisory KB3159623, dated September 24, 2026, and is urging self-hosted customers to update quickly.

The most serious bug, CVE-2026-13016, is an SQL injection flaw. Under certain conditions, an unauthenticated user could run arbitrary SQL statements against an instance’s underlying database. ServiceNow rated it critical using the CVSS v4.0 scoring system and says it has found no evidence that any of the five flaws have been exploited in the wild.

The stakes are high because ServiceNow instances often hold IT tickets, HR records, asset inventories, and security workflows for large organizations. One exposed deployment can leak far more than a single department’s data. Teams running their own instances now need to confirm their patch levels and check logs for signs of tampering.

Who Needs to Act, and Which Versions Fix the Problem

According to ServiceNow, customers enrolled in its August Patching Program have already received the updates. Self-hosted customers are the main concern. The company recommends they apply the fixes promptly or move to a patched release.

The advisory lists these releases as containing the September 2026 remediations:

The first step is an inventory. Administrators should identify every self-hosted AI Platform instance, confirm its release and patch level, and upgrade any instance that isn’t on one of the versions above.

How the Five Vulnerabilities Compare

Four of the five flaws can be reached without authentication, which is what makes this advisory stand out. The fifth requires a valid login.

The SQL injection flaw

ServiceNow tracks CVE-2026-13016 internally as PRB2036897. If exploited, it could give attackers access to instance data beyond intended permissions, along with the ability to alter it. What is exposed depends on how an organization uses the platform. It could include service management tickets, configuration records, workflow data, or employee information.

Missing authorization and privilege escalation

CVE-2026-86860, tracked as PRB2050429, comes from absent authorization checks. ServiceNow says an unauthenticated user could pull data outside the intended scope and escalate privileges in the process.

Write access without a login

CVE-2026-86858 is rated high rather than critical, but it deserves attention because it allows changes, not just reads. An unauthenticated user could create, modify, or delete records. That opens the door to integrity attacks, such as altering incident records or planting false change management entries. Tampering like this can go unnoticed for longer than data theft.

ServiceNow said the issues surfaced through several channels: internal testing, customer security assessments, responsible disclosure reports, and its bug bounty program. Each was fixed independently.

What Security Teams Should Check After Patching

Patching closes the holes but doesn’t show whether anyone used them first. ServiceNow’s guidance points teams toward several signals in their logs:

Unfamiliar sources in instance access logs

Unexpected administrative activity

Unusual record changes, especially bulk edits or deletions

Database-related errors that could reflect injection attempts

Instances handling customer, employee, or security operations data should go to the top of the queue.

This isn’t the first time a ServiceNow platform flaw has drawn urgent warnings. In July 2024, a critical input validation bug, CVE-2024-4879, was exploited soon after disclosure. The U.S. Cybersecurity and Infrastructure Security Agency later added it to its Known Exploited Vulnerabilities catalog. There are no exploitation reports for the current flaws, but that history shows how quickly attackers can move once technical details become public.