AI analysis
CVE-2026-13016 is a critical (CVSS 4.0: 9.3) SQL injection vulnerability in the ServiceNow AI Platform that, in certain circumstances, allows an unauthenticated attacker over the network to execute arbitrary SQL statements against the instance's underlying database. Successful exploitation gives the attacker the ability to read or modify instance data well beyond what was intended, including potentially sensitive business records held in the platform. ServiceNow's own hosted (SaaS) instances received an automatic security update, but partner-hosted and self-hosted deployments must apply the update or upgrade to a patched release manually. No malicious exploitation has been observed to date, there is no known public proof of concept, and the issue is not on the CISA KEV catalog, though the unauthenticated attack vector and high impact make prompt patching a priority.
What to do: Self-hosted and partner-hosted customers should immediately apply the ServiceNow security update or upgrade to a patched release, since no specific patched version numbers were disclosed — contact ServiceNow or check the advisory/patch portal for the appropriate release for your instance. Verify with ServiceNow that hosted instances received the automatic remediation. Until patched, restrict internet-facing access to the instance and review audit logs and database activity for anomalous unauthenticated requests or unexpected data access and modification.
Affected
| ServiceNow AI Platform (ServiceNow instance/platform) | — |
Estimated exposure
largeTens of thousands of enterprise deployments (~25,000+ ServiceNow customers, with multiple instances each, and tens of thousands of ServiceNow login pages… — ServiceNow's publicly reported enterprise customer count (~25,000+ organizations, including most of the Fortune 500), multiplied by typical multi-instance deployment patterns, plus public internet scan counts of exposed ServiceNow instance…
Description
ServiceNow has remediated a SQL injection vulnerability that was identified in the ServiceNow AI Platform. This vulnerability could enable an unauthenticated user, in certain circumstances, to execute arbitrary SQL statements against the instance's underlying database and gain access to, or modify, instance data beyond what was intended. ServiceNow deployed a security update to hosted instances and ServiceNow provided the update to our partners and self-hosted customers. We are not currently aware of malicious exploitation against ServiceNow instances. We recommend customers promptly apply appropriate updates or upgrade to a patched release if they have not already done so.