Executive brief
ServiceNow's AI platform contained a code injection vulnerability that could allow unauthenticated attackers to execute arbitrary code and access or modify sensitive instance data. ServiceNow has patched the vulnerability across its hosted instances and provided updates to self-hosted customers. The company reports no current evidence of active exploitation in the wild.
Technical details
A code injection vulnerability in ServiceNow's AI platform could be exploited by unauthenticated attackers under certain circumstances to execute arbitrary code within the platform. The vulnerability permits attackers to gain unauthorized access to instance data or modify data beyond intended scope. ServiceNow has deployed security updates to hosted instances and made patches available to partners and self-hosted customers. No active exploitation has been reported as of the advisory date.
Affected products
- ServiceNow AI platform
Timeline
- 2026-08-27: disclosed
- 2026-08-27: patched: Security update deployed to hosted instances; patches provided to partners and self-hosted customers