What happened
ServiceNow remediated a cluster of authorization issues in the ServiceNow AI Platform (2026-09-24): missing authorization enabling unauthenticated instance-data extraction and privilege escalation (CVE-2026-86860, CVSS 9.3 sub-system impact), an unauthenticated improper-access-control issue allowing create/modify/delete beyond intent (CVE-2026-86858, CVSS 8.7), and two authorization bypasses (CVE-2026-86859 unauthenticated and CVE-2026-86857 authenticated, CVSS 8.4-8.7). Patches per family hotfix list.
Why it matters
Together with the SQLi (CVE-2026-13016) these represent a broadened unauthenticated attack surface inside an enterprise-wide AI workflow platform, where one seniority of access to AI features can cross into tenant data creation/modification/deletion - direct privilege-escalation risk for AI deployments on ServiceNow.
Attack vector
Unauthenticated (or low-privileged authenticated) requests to AI Platform endpoints that omit authorization checks, reading/creating/modifying/deleting tenant data beyond intended scope.
Affected systems
ServiceNow AI Platform < (Yokohama Patch 13 HF5a / Zurich Patch 10 HF3b+ / Australia Patch 5)
Mitigation
Apply ServiceNow security update per KB3159623; audit AI Platform instance data for unauthorized changes.