Home › Intelligence › Brief
VULNERABILITY BRIEF🟠 High Vulnerability

Multiple Critical Vulnerabilities in ServiceNow AI Platform Could Permit Unauthorized Access

ServiceNow disclosed four CVEs affecting its AI Platform that could let attackers read, modify, or delete data they shouldn’t. Organizations must patch quickly and prove access‑control remediation to maintain audit readiness.

LiveThreat™ Intelligence · 📅 September 26, 2026· 📰 cisecurity.org
🟠
Severity
High
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
3 sector(s)
✅
Actions
3 recommended
📰
Source
cisecurity.org

Multiple Critical Vulnerabilities in ServiceNow AI Platform Could Permit Unauthorized Access

What Happened — ServiceNow disclosed four CVEs (CVE‑2026‑86857, CVE‑2026‑86858, CVE‑2026‑13016, CVE‑2026‑86859) affecting its AI Platform. The flaws include authorization bypass, improper access control, and a SQL injection that could let authenticated or unauthenticated users read, modify, or delete data they should not access. No public exploitation has been reported yet.

Why It Matters for Trust & Control Assurance

  • The vulnerabilities test the access‑control control objective that underpins many frameworks (e.g., NIST CSF, ISO 27001). Continuous evidence of proper authorization policies is essential to prove you’re not exposed to such gaps.
  • Demonstrating that you have a real‑time control‑mapping process lets auditors see you can detect, remediate, and document fixes for similar flaws across cloud‑based SaaS services.
  • A robust access‑control program, coupled with automated evidence collection, provides the defensible audit trail that a breach‑or‑exploit scenario would otherwise undermine.

Who Is Affected – Large and medium government agencies, large and medium enterprises, and any organization that runs ServiceNow AI Platform instances (Yokohama, Zurich, Australia releases).

Recommended Actions

  • Verify your ServiceNow instance version and apply the latest hot‑fixes (Yokohama ≥ Patch 13 Hot Fix 5a, Zurich ≥ Patch 10 Hot Fix 4a, Australia ≥ Patch 2 Hot Fix 4b).
  • Map the identified CVEs to your access‑control controls and capture remediation evidence in your continuous‑monitoring system.
  • Conduct a focused access‑control review of all ServiceNow integrations to ensure least‑privilege and proper segregation of duties.

Source: CIS Advisory 2026‑102

Technical Notes

  • Attack vector: Exploit of public‑facing application (initial access) via authorization bypass and SQL injection.
  • CVE‑2026‑86857 – Authenticated authorization bypass.
  • CVE‑2026‑86858 – Unauthenticated improper access control (create/modify/delete).
  • CVE‑2026‑13016 – Unauthenticated SQL injection.
  • CVE‑2026‑86859 – Unauthenticated authorization bypass.

Source: CIS Advisory 2026‑102

📰 Original Source
https://www.cisecurity.org/advisory/multiple-vulnerabilities-in-servicenows-ai-platform-could-allow-for-unauthorized-access_2026-102 ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Access is where most audits get tested.

Verisq AI Trust Operations maps incidents like this to your access controls and collects the evidence continuously, keeping your trust posture defensible.

See where you'd stand with Verisq AI Trust Operations →