ServiceNow CVE-2026-86857
Authenticated Authorization Bypass in the ServiceNow AI Platform
Risk & exploitation
Detection seeds: none indexed — public detection content (Sigma) that references this id; a seed is a starting point for a rule, not a verified fingerprint.
Disclosed 6 days ago, so the exploitation signals this score leans on — EPSS, CISA KEV and public-exploit indexing — have not had time to mean anything yet. Priority follows CVSS severity until they do, rather than reporting their absence as safety. EPSS (FIRST) estimates a low likelihood of exploitation in the next 30 days (2026-09-27). Priority blends CVSS, EPSS, KEV and public-exploit availability — operational prioritization, not a NIS2/DORA reporting determination.
Summary
What it is. An authorization bypass in the ServiceNow AI Platform lets a user who is already logged in reach data they are not entitled to. It is the only one of the five September 2026 CVEs that requires credentials.
Are you exposed? Any Yokohama, Zurich or Australia instance that has not reached the patch levels listed below. For a direct answer, use the Check your instance link further down this page and enter your release and patch level.
On Xanadu or older, ServiceNow published no fix in this batch — it patches only releases still in support. That is not the same as being unaffected. No fixed version exists for those releases, so nothing on this page can clear you, and the instance should be treated as exposed until it is upgraded.
What to do. Patch. Needing a login narrows who can exploit it; on an instance with self-registration, a customer-facing portal or a large contractor population, that population is larger than it first appears.
Has it been used? Not visibly. There is no CISA KEV entry, no public exploit in the sources tracked here, and ServiceNow reports no evidence of malicious exploitation.
For analysts. ServiceNow's CVSS 4.0 vector is AV:N/AC:L/AT:N/PR:L/UI:N with VC:H/VI:N/VA:N and SC:H/SI:H. NVD has not assigned a CWE for this record, and none is guessed here. The internal problem record is PRB2033195. PR:L is the single metric separating it from CVE-2026-86859; the High subsequent-system metrics mean ServiceNow scored the consequence as reaching past the vulnerable component, the same way it did for CVE-2026-86860.
What this page can tell you. The patch levels above were checked by a person against ServiceNow's KB3159625 on 2026-09-25, so the free check gives you a straight patched-or-affected answer from your release and patch level. Nobody has written a detection rule for this CVE yet, so the paid log check will tell you it could not look rather than guess — it never reports an attack it did not actually see.
Affected releases & fixed-in
| Release | Fixed in |
|---|---|
| Australia | Patch 2 Hot Fix 4b W32 / Patch 4 Hot Fix 3 / Patch 5 |
| Zurich | Patch 10 Hot Fix 3b / Patch 10 Hot Fix 4a W32 / Patch 11 Hot Fix 3 |
| Yokohama | Patch 13 Hot Fix 5a |
Source & attribution
Per-release fixed-in verified 2026-09-25 against ServiceNow's 'September 2026 CVE Advisory Notification' (KB3159625, login-gated, reviewed by a human) and cross-checked against the ServiceNow-authored CVE Record (CNA shortName: SN) as served by NVD. The two sources agree on all seven fixed-in boundaries across the three release families (Yokohama, Zurich, Australia). ServiceNow's CVE Records for this batch cite KB3159623; the article reviewed was KB3159625. No fix is published for Xanadu or earlier in this batch — those families are out of support, which is not the same as unaffected.
Regulatory mapping
- NIS2 Art.21§2(a)
- NIS2 Art.21§2(e)
- NIS2 Art.23§1
- DORA Art.9§1
- DORA Art.10§1
- DORA Art.19§1
- ISO A.8.8
- ISO A.8.3
- GDPR Art.32
- GDPR Art.33
Decision support, not a reporting determination.
References
- https://github.com/advisories/GHSA-3g9f-q9vc-qffh
- https://nvd.nist.gov/vuln/detail/CVE-2026-86857
- https://support.servicenow.com/kb?id=kb_article_view&sysparm_article=KB3159623
- https://support.servicenow.com/kb?id=kb_article_view&sysparm_article=KB3159625
- https://support.servicenow.com/kb?id=kb_article_view&sysparm_article=KB3159626
- https://www.cve.org/CVERecord?id=CVE-2026-86857
Data: GitHub Advisory Database (CC-BY 4.0), NVD, the CISA KEV catalog, FIRST EPSS, Exploit-DB, and Nuclei templates.