AI analysis
CVE-2026-86859 is an authorization bypass in the ServiceNow AI Platform that allows an unauthenticated attacker, over the network, to access data within a ServiceNow instance that they are not entitled to see, potentially enabling further unintended access. Exploitation requires no privileges and no user interaction, and the CVSS 4.0 vector (8.7, AV:N/AC:L/PR:N, VC:H) reflects a purely confidentiality-focused impact with no direct effect on integrity or availability. Both hosted instances and self-hosted/partner-managed deployments were affected; ServiceNow has already pushed the fix to its own hosted instances and supplied updates to partners and self-hosted customers. Because the flaw grants data access rather than code execution, the practical risk is exposure of sensitive business records (HR, ITSM, customer data) stored in the platform. No malicious exploitation has been observed, no public PoC exists, and the CVE is not in CISA's KEV catalog.
What to do: Self-hosted and partner-managed customers should immediately apply the ServiceNow-provided security update or upgrade to a patched release, then verify the instance version against ServiceNow's security advisory. Audit instance logs for unauthenticated or anomalous record access to data outside expected entitlements, and review ACL/role configurations for unintended access paths. Hosted-instance customers should confirm with ServiceNow that their instance received the automatic update.
Affected
| ServiceNow AI Platform (hosted instances and self-hosted/partner deployments) | — |
Estimated exposure
moderateResidual vulnerable footprint likely in the hundreds to low thousands of self-hosted/partner-managed instances (hosted tenants, the bulk of ServiceNow's… — ServiceNow automatically remediated all of its hosted instances before disclosure, and prior ServiceNow vulnerability responses (e.g., the 2024 unauthenticated-access flaws) showed only on the order of 700–2,000 internet-exposed…
Description
ServiceNow has remediated an authorization bypass security issue that was identified in the ServiceNow AI Platform. This security issue, if exploited, could enable an unauthenticated user to access data within the ServiceNow AI Platform that the user otherwise would not be entitled to access, potentially enabling further unintended access. ServiceNow deployed a security update to hosted instances and ServiceNow provided the update to our partners and self-hosted customers. We are not currently aware of malicious exploitation against ServiceNow instances. We recommend customers promptly apply appropriate updates or upgrade to a patched release if they have not already done so.