securityonline.info 25 Sept 2026, 03:15 UTC

ServiceNow Patches Critical AI Flaws Enabling Data Theft and SQL Injection

ServiceNow Patches Critical AI Flaws Enabling Data Theft and SQL Injection

SERVICENOW released security patches on 24 September 2026 for five vulnerabilities in its AI Platform. The flaws affect the Yokohama, Zurich and Australia release branches before the September 2026 patch cycle, with two rated critical and three high. The most serious issues are CVE-2026-13016, an unauthenticated SQL injection flaw rated 9.3 under CVSSv4, and CVE-2026-86860, an unauthenticated sensitive-data disclosure flaw also rated 9.3.

The remaining vulnerabilities are CVE-2026-86858, an unauthenticated privilege-escalation issue via GraphQL (8.7); CVE-2026-86859, an unauthenticated arbitrary-record disclosure flaw (8.7); and CVE-2026-86857, an authorisation bypass (8.4).

The article says ServiceNow identified the defects through internal assessments and bug-bounty programmes. The vendor stated that it had found no evidence of malicious exploitation, and no public proof-of-concept code had been published. However, the flaws could allow unauthenticated attackers to submit malicious database queries, extract instance data, or exploit missing authorisation checks. An authenticated user could also use CVE-2026-86857 to access restricted datasets.

ServiceNow has reportedly updated cloud-hosted instances automatically. Administrators of self-hosted deployments should apply the security update for their release branch, including Yokohama Patch 13 Hot Fix 5a or Zurich Patch 10 Hot Fix 3b; the listed fixes also include Zurich Patch 10 Hot Fix 4a W32.

View full article

Article by CyberSIXT