Critical ServiceNow Vulnerabilities Let Attackers Bypass Authorization
Key Takeaways ServiceNow has released critical security updates addressing five vulnerabilities within its AI Platform. Two critical flaws (CVE-2026-13016 and CVE-2026-86860) could allow...
Key Takeaways
- ServiceNow has released critical security updates addressing five vulnerabilities within its AI Platform.
- Two critical flaws (CVE-2026-13016 and CVE-2026-86860) could allow unauthenticated attackers to access, modify, or extract sensitive instance data.
- The vulnerabilities were identified through various channels, including internal testing and bug bounty programs.
- While no in-the-wild exploitation has been observed, immediate patching is strongly recommended, especially for internet-facing instances.
ServiceNow has issued urgent security advisories and released patches for a set of five vulnerabilities affecting its AI Platform, two of which are rated critical. These flaws could potentially allow unauthorized individuals to bypass authentication mechanisms and gain access to, modify, or exfiltrate sensitive data from affected instances. The company is strongly urging self-hosted users to verify their current versions and apply the necessary updates without delay.
Table Of Content
The security advisory from ServiceNow details the vulnerabilities, identified as CVE-2026-86857, CVE-2026-86858, CVE-2026-13016, CVE-2026-86859, and CVE-2026-86860. These issues came to light through a combination of internal testing, customer assessments, responsible disclosures, and the vendor’s bug bounty program.
Although ServiceNow has confirmed that there is currently no evidence of these vulnerabilities being actively exploited in the wild, the potential technical repercussions necessitate prompt action. Rapid patching is particularly crucial for instances that are exposed to the public internet or are integral to sensitive enterprise workflows and data management.
Critical Vulnerabilities Detailed
The most severe vulnerability, CVE-2026-13016, is a critical SQL injection flaw impacting the ServiceNow AI Platform. Under specific conditions, an unauthenticated attacker could leverage this vulnerability to execute arbitrary SQL commands against the underlying database of an affected instance. Successful exploitation of this flaw could enable an attacker to read, modify, or even manipulate data stored within the ServiceNow instance. This poses significant risks for organizations that rely on ServiceNow for critical functions such as IT service management, security incident response, employee request processing, asset tracking, customer information, and various internal business operations.
Another critical vulnerability, CVE-2026-86860, is an authorization bypass issue. This flaw could permit an unauthenticated attacker to extract instance data, circumventing established access controls and allowing access to information beyond their intended permissions. ServiceNow has cautioned that exploitation of these critical flaws could lead to privilege escalation, granting attackers elevated access levels or data permissions they should not possess.
The September 2026 advisory KB3159623 further outlines three additional high-severity vulnerabilities related to authorization and access control weaknesses:
- CVE-2026-86857: This is an authorization bypass flaw that could allow an authenticated user to access ServiceNow AI Platform data for which they lack proper entitlements, potentially leading to broader unintended access within the environment.
- CVE-2026-86858: An improper access control issue, this vulnerability could, under certain circumstances, enable an unauthenticated attacker to create, modify, or delete instance data outside of their authorized permissions. Such actions could disrupt operational workflows, corrupt records, or compromise the integrity of security and operational data.
- CVE-2026-86859: Similar to CVE-2026-86857, this is another authorization bypass vulnerability. However, this specific flaw could allow an unauthenticated attacker to access restricted data within the ServiceNow AI Platform.
ServiceNow has confirmed that customers enrolled in its August Patching Program have already received the necessary fixes. Self-hosted customers are urged to upgrade their instances or apply the relevant updates immediately. Patched releases include Yokohama Patch 13 Hot Fix 5a, Zurich Patch 10 Hot Fix 4a W32, and Australia Patch 2 Hot Fix 4b W32. Additional remediated versions include Zurich Patch 10 Hot Fix 3b, Zurich Patch 11 Hot Fix 3, Australia Patch 4 Hot Fix 3, and Australia Patch 5.
What You Should Do
- Immediately identify and confirm your current ServiceNow AI Platform version.
- Apply the recommended patches or upgrade to a remediated release as detailed by ServiceNow, prioritizing internet-facing instances.
- Review and audit administrative access privileges within your ServiceNow environment.
- Implement enhanced monitoring for unusual database queries, unexpected data modifications, or any unauthorized access attempts after applying patches.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.