ServiceNow Patches Five AI Platform Flaws, Including Critical CVE-2026-13016 SQL Injection and CVE-2026-86860 Data Extraction Vulnerability

ServiceNow Patches Five AI Platform Flaws, Including Critical CVE-2026-13016 SQL Injection and CVE-2026-86860 Data Extraction Vulnerability

ServiceNow Patches Five AI Platform Flaws, Including Critical CVE-2026-13016 SQL Injection and CVE-2026-86860 Data Extraction Vulnerability

ServiceNow has released security updates fixing five vulnerabilities in its AI Platform, including two rated critical: a SQL injection flaw and a missing-authorization bug that could let unauthenticated attackers read, modify or extract sensitive instance data. The advisory, tracked as KB3159623 and published September 24, says ServiceNow has found no evidence of exploitation in the wild — but the unauthenticated attack paths make rapid patching important, especially for internet-exposed instances.

CVE-2026-13016 is the most serious issue: a critical SQL injection (rated with the CVSS v4.0 calculator, tracked internally as PRB2036897) that in certain circumstances lets an unauthenticated attacker execute arbitrary SQL commands against an affected instance's underlying database — reading, modifying or manipulating the data stored in it. CVE-2026-86860, also critical, is a missing-authorization vulnerability that allows an unauthenticated attacker to extract instance data beyond intended access controls, resulting in privilege escalation (PRB2050429).

The advisory details three additional high-severity authorization and access-control weaknesses. CVE-2026-86857 lets authenticated users reach AI Platform data they are not entitled to view; CVE-2026-86858 allows unauthenticated attackers to create, modify or delete instance data — a direct integrity risk for workflows, incident records and change management entries; and CVE-2026-86859 lets unauthenticated attackers access restricted AI Platform data. ServiceNow says the flaws were found through internal testing, customer security assessments, responsible disclosure submissions and its bug bounty program.

What is at stake is the platform's role as enterprise central nervous system: ITSM tickets, asset records, HR data, workflow records, security incident data and customer information all live in ServiceNow. Customers on ServiceNow's August Patching Program already have the fixes. Self-hosted customers should upgrade to a patched release now: Yokohama Patch 13 Hot Fix 5a, Zurich Patch 10 Hot Fix 4a W32, or Australia Patch 2 Hot Fix 4b W32, with additional remediated releases in Zurich P10 HF3b, Zurich P11 HF3, Australia P4 HF3 and Australia P5.

What Should You Do?

  1. Inventory every self-hosted ServiceNow instance — confirm the release and patch level against the fixed list, and prioritize anything internet-exposed.
  2. Apply the update immediately. Unauthenticated SQL injection plus data extraction is about the worst combination a platform can disclose; the exposure window is the risk.
  3. Hunt for signs of attempted exploitation: review access logs for unusual database queries, unexpected record modifications, and administrative access changes — before and after patching.
  4. Cloud-hosted customers: confirm your instance's patch status with your account team rather than assuming the provider handled it.

The WAF Angle

A critical, unauthenticated SQL injection in a widely deployed enterprise platform is the textbook case for virtual patching: the CVE is public, the affected versions are enumerated, and a WAF in front of the instance can buy patch-cycle time with tuned SQL injection rules. The subtler lesson is that "internal" platforms are usually neither internal nor low-risk — ServiceNow instances aggregate workflow, HR and security data behind web interfaces that often face the internet for remote staff and partners. Treat platform CVEs with unauthenticated attack paths as immediate WAF-signature priorities, and give the SaaS your employees log into daily the same perimeter protection you would give a public website.

Sources