← All CVEs & advisories

ServiceNow CVE-2026-86857

Authenticated Authorization Bypass in the ServiceNow AI Platform

AuthBypassCVSS 4.0 8.4Priority HighDisclosed 2026-09-24Verified

Risk & exploitation

PriorityHigh · severity-led
EPSS0.002 · 13.9th pct
CISA KEVNo
Public exploitNone indexed
Exploit maturity— No approved exploit evidence

Detection seeds: none indexed — public detection content (Sigma) that references this id; a seed is a starting point for a rule, not a verified fingerprint.

Disclosed 6 days ago, so the exploitation signals this score leans on — EPSS, CISA KEV and public-exploit indexing — have not had time to mean anything yet. Priority follows CVSS severity until they do, rather than reporting their absence as safety. EPSS (FIRST) estimates a low likelihood of exploitation in the next 30 days (2026-09-27). Priority blends CVSS, EPSS, KEV and public-exploit availability — operational prioritization, not a NIS2/DORA reporting determination.

Summary

What it is. An authorization bypass in the ServiceNow AI Platform lets a user who is already logged in reach data they are not entitled to. It is the only one of the five September 2026 CVEs that requires credentials.

Are you exposed? Any Yokohama, Zurich or Australia instance that has not reached the patch levels listed below. For a direct answer, use the Check your instance link further down this page and enter your release and patch level.

On Xanadu or older, ServiceNow published no fix in this batch — it patches only releases still in support. That is not the same as being unaffected. No fixed version exists for those releases, so nothing on this page can clear you, and the instance should be treated as exposed until it is upgraded.

What to do. Patch. Needing a login narrows who can exploit it; on an instance with self-registration, a customer-facing portal or a large contractor population, that population is larger than it first appears.

Has it been used? Not visibly. There is no CISA KEV entry, no public exploit in the sources tracked here, and ServiceNow reports no evidence of malicious exploitation.

For analysts. ServiceNow's CVSS 4.0 vector is AV:N/AC:L/AT:N/PR:L/UI:N with VC:H/VI:N/VA:N and SC:H/SI:H. NVD has not assigned a CWE for this record, and none is guessed here. The internal problem record is PRB2033195. PR:L is the single metric separating it from CVE-2026-86859; the High subsequent-system metrics mean ServiceNow scored the consequence as reaching past the vulnerable component, the same way it did for CVE-2026-86860.

What this page can tell you. The patch levels above were checked by a person against ServiceNow's KB3159625 on 2026-09-25, so the free check gives you a straight patched-or-affected answer from your release and patch level. Nobody has written a detection rule for this CVE yet, so the paid log check will tell you it could not look rather than guess — it never reports an attack it did not actually see.

Affected releases & fixed-in

ReleaseFixed in
AustraliaPatch 2 Hot Fix 4b W32 / Patch 4 Hot Fix 3 / Patch 5
ZurichPatch 10 Hot Fix 3b / Patch 10 Hot Fix 4a W32 / Patch 11 Hot Fix 3
YokohamaPatch 13 Hot Fix 5a
Source & attribution

Per-release fixed-in verified 2026-09-25 against ServiceNow's 'September 2026 CVE Advisory Notification' (KB3159625, login-gated, reviewed by a human) and cross-checked against the ServiceNow-authored CVE Record (CNA shortName: SN) as served by NVD. The two sources agree on all seven fixed-in boundaries across the three release families (Yokohama, Zurich, Australia). ServiceNow's CVE Records for this batch cite KB3159623; the article reviewed was KB3159625. No fix is published for Xanadu or earlier in this batch — those families are out of support, which is not the same as unaffected.

Regulatory mapping

Decision support, not a reporting determination.

Check your instance for CVE-2026-86857 →

References

Data: GitHub Advisory Database (CC-BY 4.0), NVD, the CISA KEV catalog, FIRST EPSS, Exploit-DB, and Nuclei templates.

ServiceNow CVE-2026-86857: affected versions & exposure check — Nowisor | nowisor