ServiceNow has disclosed five vulnerabilities affecting its AI Platform, including two critical flaws that could allow unauthenticated attackers to execute arbitrary SQL commands, extract sensitive instance data, modify records, and escalate privileges.
The security advisory, published in September 2026 and tracked as KB3159623 on September 24, details the following vulnerabilities: CVE-2026-86857, CVE-2026-86858, CVE-2026-13016, CVE-2026-86859, and CVE-2026-86860.
ServiceNow stated that it has found no evidence of these vulnerabilities being exploited maliciously in the wild.
Critical SQL Injection Risk
The most severe issue, CVE-2026-13016, is a critical SQL injection vulnerability within the ServiceNow AI Platform. Under certain circumstances, an unauthenticated attacker could execute arbitrary SQL statements against the underlying database of an affected instance.
Successful exploitation could allow an attacker to access or alter instance data beyond intended permissions, potentially exposing sensitive enterprise records stored in ServiceNow.
This might include IT service management tickets, asset data, workflow records, HR-related information, configuration data, and other business-critical content, depending on how the organization uses the platform.
ServiceNow classified this issue as critical using the CVSS v4.0 calculator. It is tracked internally as PRB2036897.
Another critical vulnerability, CVE-2026-86860, arises from missing authorization controls. This flaw could allow an unauthenticated attacker to extract data from a vulnerable ServiceNow instance beyond the intended scope, resulting in privilege escalation. It is tracked as PRB2050429.
Additional High-Severity Flaws
The advisory also addresses three high-severity authorization and access control weaknesses:
| CVE | Severity | Vulnerability type | Potential impact |
|---|---|---|---|
| CVE-2026-86857 | High | Authorization bypass | Authenticated users could access AI Platform data they are not authorized to view |
| CVE-2026-86858 | High | Improper access control | Unauthenticated attackers could create, modify, or delete instance data |
| CVE-2026-86859 | High | Authorization bypass | Unauthenticated attackers could access restricted AI Platform data |
| CVE-2026-13016 | Critical | SQL injection | Unauthenticated attackers could run arbitrary SQL and access or modify data |
| CVE-2026-86860 | Critical | Missing authorization | Unauthenticated attackers could extract data and escalate privileges |
CVE-2026-86858 is particularly significant as it could allow unauthenticated users to create, modify, or delete instance data. This may enable integrity attacks against business workflows, incident records, change management entries, or other data maintained by the affected deployment.
ServiceNow discovered these vulnerabilities through internal testing, customer security assessments, responsible disclosure submissions, and its bug bounty program. Each issue was remediated independently.
Patched Releases
Customers enrolled in ServiceNow’s August Patching Program have already received the appropriate updates. ServiceNow recommends that self-hosted customers promptly apply the available fixes or upgrade to a patched release. The following releases include the September 2026 remediations:
| ServiceNow AI Platform release | Patched version |
|---|---|
| Yokohama | Patch 13 Hot Fix 5a |
| Zurich | Patch 10 Hot Fix 4a W32 |
| Australia | Patch 2 Hot Fix 4b W32 |
| Zurich | Patch 10 Hot Fix 3b or Patch 11 Hot Fix 3 |
| Australia | Patch 4 Hot Fix 3 or Patch 5 |
Organizations should identify all self-hosted ServiceNow AI Platform instances, confirm their release and patch levels, and immediately upgrade to one of the fixed versions.
Security teams should also review instance access logs, administrative activity, unusual record modifications, and unexpected database-related errors for signs of attempted exploitation.
Given the unauthenticated attack paths and critical SQL injection flaw, organizations should prioritize these updates, especially where ServiceNow instances handle sensitive operational, customer, employee, or security workflow data.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC

