Authorization Bypass Vulnerability in ServiceNow AI Platform
CVE-2026-86857

8.4HIGH

Key Information:

Vendor

Servicenow

Vendor
CVE Published:
24 September 2026

What is CVE-2026-86857?

An issue has been identified in the ServiceNow AI Platform that allows unauthorized access to sensitive data. This vulnerability enables an authenticated user to bypass permissions, resulting in potential access to information that should be restricted. ServiceNow has addressed this issue with an update for all hosted instances and distributed patches to partners and self-hosted customers. It is vital for users to apply these updates promptly to safeguard their data and maintain security integrity.

Affected Version(s)

ServiceNow AI Platform 0

ServiceNow AI Platform 0

ServiceNow AI Platform 0

References

CVSS V4

Score:
8.4
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.