Executive brief
ServiceNow's AI platform contained an access control flaw that could allow unauthenticated users to create or modify instance data in certain circumstances, potentially bypassing security controls. The vulnerability has been patched and deployed to all hosted instances, with no known active exploitation reported.
Technical details
An improper access control vulnerability in the ServiceNow AI platform failed to properly restrict data modification operations. The flaw could enable an unauthenticated attacker to create or modify instance data beyond intended scope, resulting in privilege escalation. ServiceNow has deployed security updates to hosted instances and provided patches to partners and self-hosted customers. No exploitation in the wild has been identified.
Affected products
- ServiceNow AI Platform
Timeline
- 2026-08-27: disclosed
- 2026-08-27: patched: Security update deployed to hosted instances; patches provided to partners and self-hosted customers