Authorization Bypass Vulnerability in ServiceNow AI Platform
CVE-2026-86859

8.7HIGH

Key Information:

Vendor

Servicenow

Vendor
CVE Published:
24 September 2026

What is CVE-2026-86859?

The ServiceNow AI Platform has addressed a significant authorization bypass vulnerability that could allow unauthorized users to gain access to sensitive data. If exploited, this vulnerability enables users to bypass security controls, leading to unauthorized access to data that should be protected. ServiceNow has released security updates to mitigate this issue across hosted instances and has advised partners and self-hosted customers to apply the updates promptly to ensure ongoing protection against potential misuse.

Affected Version(s)

ServiceNow AI Platform 0

ServiceNow AI Platform 0

ServiceNow AI Platform 0

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.