ServiceNow CVE-2026-86860
Unauthenticated Missing Authorization Leading to Privilege Escalation
Risk & exploitation
Detection seeds: none indexed — public detection content (Sigma) that references this id; a seed is a starting point for a rule, not a verified fingerprint.
Disclosed 6 days ago, so the exploitation signals this score leans on — EPSS, CISA KEV and public-exploit indexing — have not had time to mean anything yet. Priority follows CVSS severity until they do, rather than reporting their absence as safety. EPSS (FIRST) estimates a low likelihood of exploitation in the next 30 days (2026-09-27). Priority blends CVSS, EPSS, KEV and public-exploit availability — operational prioritization, not a NIS2/DORA reporting determination.
Summary
What it is. A missing authorization check in the ServiceNow AI Platform lets someone who has never logged in read instance data they were never meant to see, and ServiceNow states the outcome is privilege escalation. It is one of two critical CVEs in the batch ServiceNow published on 24 September 2026.
Are you exposed? Any Yokohama, Zurich or Australia instance that has not reached the patch levels listed below. For a direct answer, use the Check your instance link further down this page and enter your release and patch level.
On Xanadu or older, ServiceNow published no fix in this batch — it patches only releases still in support. That is not the same as being unaffected. No fixed version exists for those releases, so nothing on this page can clear you, and the instance should be treated as exposed until it is upgraded.
What to do. Patch. The flaw requires no credentials, so there is no role or ACL change that closes it from inside the platform.
Has it been used? Not visibly. There is no CISA KEV entry, no public exploit in the sources tracked here, and ServiceNow reports no evidence of malicious exploitation. That is worth knowing and it is not a reason to wait.
For analysts. ServiceNow's CVSS 4.0 vector is AV:N/AC:L/AT:N/PR:N/UI:N with VC:H/VI:N/VA:N but SC:H/SI:H, and the CWE is CWE-862. The internal problem record is PRB2050429. The High subsequent-system confidentiality and integrity metrics are what carry the score to 9.3 despite no direct integrity or availability impact — they are the scoring expression of ServiceNow's own phrase "resulting in privilege escalation", meaning the consequence is rated as reaching past the vulnerable component.
What this page can tell you. The patch levels above were checked by a person against ServiceNow's KB3159625 on 2026-09-25, so the free check gives you a straight patched-or-affected answer from your release and patch level. Nobody has written a detection rule for this CVE yet, so the paid log check will tell you it could not look rather than guess — it never reports an attack it did not actually see.
Affected releases & fixed-in
| Release | Fixed in |
|---|---|
| Australia | Patch 2 Hot Fix 4b W32 / Patch 4 Hot Fix 3 / Patch 5 |
| Zurich | Patch 10 Hot Fix 3b / Patch 10 Hot Fix 4a W32 / Patch 11 Hot Fix 3 |
| Yokohama | Patch 13 Hot Fix 5a |
Source & attribution
Per-release fixed-in verified 2026-09-25 against ServiceNow's 'September 2026 CVE Advisory Notification' (KB3159625, login-gated, reviewed by a human) and cross-checked against the ServiceNow-authored CVE Record (CNA shortName: SN) as served by NVD. The two sources agree on all seven fixed-in boundaries across the three release families (Yokohama, Zurich, Australia). ServiceNow's CVE Records for this batch cite KB3159623; the article reviewed was KB3159625. No fix is published for Xanadu or earlier in this batch — those families are out of support, which is not the same as unaffected.
Regulatory mapping
- NIS2 Art.21§2(a)
- NIS2 Art.21§2(e)
- NIS2 Art.23§1
- DORA Art.9§1
- DORA Art.10§1
- DORA Art.19§1
- ISO A.8.8
- ISO A.8.3
- GDPR Art.32
- GDPR Art.33
Decision support, not a reporting determination.
References
- https://github.com/advisories/GHSA-hm4f-jpr2-fpx4
- https://nvd.nist.gov/vuln/detail/CVE-2026-86860
- https://support.servicenow.com/kb?id=kb_article_view&sysparm_article=KB3159623
- https://support.servicenow.com/kb?id=kb_article_view&sysparm_article=KB3159625
- https://support.servicenow.com/kb?id=kb_article_view&sysparm_article=KB3159626
- https://www.cve.org/CVERecord?id=CVE-2026-86860
Data: GitHub Advisory Database (CC-BY 4.0), NVD, the CISA KEV catalog, FIRST EPSS, Exploit-DB, and Nuclei templates.