Executive brief
ServiceNow's AI Platform contains a SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary database queries. An attacker could read or modify sensitive customer data stored in ServiceNow instances. ServiceNow has deployed security updates to hosted instances and provided patches to self-hosted customers.
Technical details
A SQL injection vulnerability exists in the ServiceNow AI Platform that permits unauthenticated users to inject and execute arbitrary SQL statements against the underlying database. The vulnerability requires no authentication and no user interaction, making it network-accessible and exploitable by remote attackers. Successful exploitation allows an attacker to read, modify, or delete data in the database beyond their intended access level. ServiceNow has released security updates for hosted instances and provided patches to partners and self-hosted customers; no active exploitation in the wild has been reported.
Affected products
- ServiceNow AI Platform <UNKNOWN>
Timeline
- 2026-08-27: disclosed
- 2026-08-27: patched: Security update deployed to hosted instances; patches provided to partners and self-hosted customers