AI analysis
CVE-2026-86858 is an improper access control flaw in the ServiceNow AI Platform that, in certain circumstances, allows an unauthenticated remote attacker to create, modify, or delete instance data beyond what was intended. The CVSS 4.0 score of 8.7 (AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H) reflects a network-reachable, low-complexity attack requiring no privileges or user interaction, with high integrity impact but no direct confidentiality or availability impact — meaning attackers could corrupt or manipulate business records such as tickets, workflows, or configuration data rather than silently read them. ServiceNow deployed a security update to its hosted instances in August 2026 and supplied the update to partners and self-hosted customers, so anyone running an unpatched self-hosted or partner-managed instance remains exposed. No public proof-of-concept exists, the flaw is not on the CISA KEV list, and ServiceNow reports no known malicious exploitation to date.
What to do: Self-hosted and partner-managed customers should immediately apply the August 2026 security update or upgrade to a patched release, and confirm that any hosted instances received the automatic deployment. Review instance audit history (e.g., record-level audit trails and updates attributed to unauthenticated/GUEST sessions) for unexpected data creation, modification, or deletion predating the patch. Verify access control lists and guest-user ACL defaults on externally reachable instances to confirm the intended restrictions are enforced after patching.
Estimated exposure
large≈tens of thousands of internet-exposed ServiceNow instances across 25,000+ enterprise customers (estimate) — ServiceNow publicly reports 25,000+ enterprise customers, and internet-wide scans (e.g., Shodan/Censys) have historically shown on the order of tens of thousands of exposed ServiceNow instance endpoints; self-hosted deployments are the…
Description
ServiceNow has remediated an improper access control security issue that was identified in the ServiceNow AI Platform. This security issue could enable an unauthenticated user, in certain circumstances, to create, modify, or delete instance data beyond what was intended. In August 2026, ServiceNow deployed a security update to hosted instances and ServiceNow provided the update to our partners and self-hosted customers. We are not currently aware of malicious exploitation against ServiceNow instances. We recommend customers promptly apply appropriate updates or upgrade to a patched release if they have not already done so.