AI analysis
ServiceNow has remediated an unauthenticated code injection vulnerability (CWE-94) in the ServiceNow AI platform, scored a maximum 10.0 in CVSS 4.0, exploitable over the network with no privileges and no user interaction. An attacker can trigger it, in certain circumstances, via crafted input to an affected instance, gaining the ability to execute arbitrary code on the platform and access or modify instance data beyond intended permission boundaries. All customers running the affected platform are in scope: ServiceNow has already deployed the fix to hosted instances, while partners and self-hosted customers must apply the provided update or upgrade to a patched release. Related reporting indicates this is one of three CVSS 10.0 ServiceNow flaws disclosed together that could allow unauthenticated code and SQL execution, though specific affected version ranges are not listed in the advisory. There is no public proof-of-concept, the flaw is not in CISA's KEV, EPSS is low (0.4% in 30 days), and ServiceNow states it is not currently aware of malicious exploitation.
What to do: Self-hosted and partner-hosted customers should promptly apply the ServiceNow-provided security update or upgrade to a patched release; hosted instances have already been updated by ServiceNow, so confirm your deployment model and current patch level against ServiceNow's advisory. Because the flaw is network-exploitable without authentication, prioritize any internet-exposed instances and review for signs of unexpected code execution or unauthorized data access. No workarounds are stated in the advisory; monitor ServiceNow PSIRT for updates, noting related coverage of three CVSS 10.0 flaws in this set.
Estimated exposure
masstens of thousands of internet-exposed ServiceNow instances (order 10^4) serving millions of users in aggregate — ServiceNow's enterprise customer base (thousands of organizations with heavy Fortune 500 adoption) and public internet scans that have repeatedly shown on the order of tens of thousands of internet-facing ServiceNow instances imply…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
ServiceNow has remediated a code injection vulnerability that was identified in the ServiceNow AI platform. This vulnerability could enable an unauthenticated user, in certain circumstances, to execute arbitrary code in the ServiceNow platform and gain access to, or modify, instance data beyond what was intended. ServiceNow deployed a security update to hosted instances and ServiceNow provided the update to our partners and self-hosted customers. We are not currently aware of malicious exploitation against ServiceNow instances. We recommend customers promptly apply appropriate updates or upgrade to a patched release if they have not already done so.