Critical ServiceNow Vulnerabilities Let Attackers Bypass Authorization – Update Now!

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com


ServiceNow released security updates for five AI Platform flaws, including two critical vulnerabilities that could let unauthenticated attackers access, modify, or extract sensitive instance data, urging self-hosted users to verify versions and patch promptly.

ServiceNow advisory covers CVE-2026-86857, CVE-2026-86858, CVE-2026-13016, CVE-2026-86859, and CVE-2026-86860, identified through internal testing, customer assessments, responsible disclosures, and its bug bounty program.

The company stated it has not identified evidence that attackers have exploited the flaws in the wild. However, the technical impact of the issues makes rapid patching important, particularly for instances exposed to the internet or connected to sensitive enterprise workflows and data.

The most serious flaw, CVE-2026-13016, is rated critical and affects the ServiceNow AI Platform. The vulnerability is a SQL injection issue that could enable an unauthenticated attacker, in certain circumstances, to execute arbitrary SQL commands against an affected instance’s underlying database.

Successful exploitation could allow an attacker to read, modify, or potentially manipulate data stored in the ServiceNow instance. This could create major risks for organizations that use ServiceNow to manage IT service operations, security incidents, employee requests, asset records, customer information, and internal business processes.

CVE-2026-86860 is also rated critical. It is a missing-authorization vulnerability that could allow an unauthenticated attacker to extract instance data beyond intended access controls.

ServiceNow Vulnerabilities

ServiceNow warned that exploitation may lead to privilege escalation, allowing attackers to gain access levels or data permissions they should not have.

The September 2026 advisory KB3159623 details three additional high-severity vulnerabilities involving authorization and access control weaknesses.

CVE-2026-86857 is an authorization bypass flaw that could let an authenticated user access ServiceNow AI Platform data they are not entitled to view. This could result in further unintended access within an affected environment.

CVE-2026-86858 is an improper access control issue. Under certain conditions, an unauthenticated attacker could create, modify, or delete instance data outside intended permissions. Such activity could disrupt workflows, alter records, or affect the integrity of security and operational data.

CVE-2026-86859 is another authorization bypass vulnerability. Unlike CVE-2026-86857, this flaw could allow an unauthenticated attacker to access data within the ServiceNow AI Platform that should be restricted.

ServiceNow said customers enrolled in its August Patching Program already received the relevant fixes. Self-hosted customers should upgrade or apply updates immediately. Patched releases include Yokohama Patch 13 Hot Fix 5a, Zurich Patch 10 Hot Fix 4a W32, and Australia Patch 2 Hot Fix 4b W32.

Additional remediated releases include Zurich Patch 10 Hot Fix 3b, Zurich Patch 11 Hot Fix 3, Australia Patch 4 Hot Fix 3, and Australia Patch 5.

Organizations should confirm their deployed version, review administrative access, and monitor for unusual database queries, unexpected data changes, or unauthorized access attempts after patching.

Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC

The post Critical ServiceNow Vulnerabilities Let Attackers Bypass Authorization – Update Now! appeared first on Cyber Security News.