Vulnerability  ·  2026-09-25

ServiceNow AI Platform: unauthenticated SQL injection into instance database (CVE-2026-13016, CVSS 9.3)

VulnerabilityHigh impactGlobalCVE-2026-13016
ServiceNow remediated a SQL injection in the ServiceNow AI Platform that could let an unauthenticated user execute arbitrary SQL against the instance's underlying database and read or modify instance data. Patches apply to Yokohama/Zurich/Australia family hotfixes (e.g. Yokohama Patch 13 Hot Fix 5a). No known malicious exploitation reported.
ServiceNow is the most widely deployed enterprise workflow/AI platform; an unauthenticated SQLi in its AI Platform component puts ticket data, entitlements and the underlying database at risk wherever the AI features are enabled - a direct enterprise AI-deployment exposure with critical severity.
Unauthenticated network request against the AI Platform component executing arbitrary SQL against the instance's underlying database.
ServiceNow AI Platform < (Yokohama Patch 13 HF5a / Zurich Patch 10 HF3b+ / Australia Patch 5)
Apply ServiceNow security update / upgrade to patched release per KB3159623 (hosted instances updated automatically).
NVD CVE-2026-13016ServiceNow KB3159623
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →