Missing Authorization in ServiceNow AI Platform Allows Unauthenticated Data Exposure
AI analysis
CVE-2026-86860 is a critical (CVSS 4.0: 9.3) missing authorization flaw in the ServiceNow AI Platform that could let an unauthenticated, remote attacker extract instance data beyond what was intended, effectively escalating privileges. Exploitation requires no credentials or user interaction and occurs when crafted requests hit the vulnerable platform under certain circumstances. The impact is primarily confidentiality of instance data, including high-value data on connected (subsequent) systems, so an attacker could read records and content they were never authorized to access. ServiceNow has already pushed the fix to its own hosted instances, so residual exposure is concentrated in self-hosted and partner-hosted deployments that must patch manually. Neither ServiceNow nor public sources report malicious exploitation to date, and no public proof of concept exists.
What to do: Apply ServiceNow's security update or upgrade to the patched release named in the vendor advisory immediately on any self-hosted or partner-hosted instance, and confirm vendor-hosted instances received the automatic update. Review instance audit logs, transaction history, and outbound data exports for unauthenticated or anomalous record access predating the patch, and rotate credentials or tokens for any data that may have been exposed. Treat any unexplained access to sensitive records, integration credentials, or connected-system data as a potential compromise.
Affected
| ServiceNow AI Platform (ServiceNow instances) | — |
Estimated exposure
moderateRoughly hundreds to low thousands of self-hosted and partner-hosted instances still requiring manual patching; ServiceNow's vendor-hosted SaaS instances were… — ServiceNow serves on the order of 10,000+ enterprise customers, but the vast majority run vendor-hosted instances that were auto-patched, leaving only the minority self-hosted/partner deployments exposed; no public instance-count scan data…
Description
ServiceNow has remediated a missing authorization vulnerability that was identified in the ServiceNow AI Platform. This vulnerability could enable an unauthenticated user, in certain circumstances, to extract instance data beyond what was intended, resulting in privilege escalation. ServiceNow deployed a security update to hosted instances and ServiceNow provided the update to our partners and self-hosted customers. We are not currently aware of malicious exploitation against ServiceNow instances. We recommend customers promptly apply appropriate updates or upgrade to a patched release if they have not already done so.