PT-2026-98256 · Servicenow · Api Platform

CVE-2026-86860

·

Published

2026-09-24

·

Updated

2026-09-27

CVSS v4.0

9.3

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions ServiceNow AI Platform (affected versions not specified)
Description A missing authorization issue exists in the ServiceNow AI Platform. This flaw could allow an unauthenticated user to extract instance data beyond the intended scope, potentially leading to privilege escalation.
Recommendations Apply the security updates provided by ServiceNow or upgrade to a patched release.

Fix

LPE

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-86860

Affected Products

Api Platform