ServiceNow AI Platform是美国ServiceNow公司的一款AI智能平台。 ServiceNow AI Platform存在安全漏洞,该漏洞源于访问控制不当,可能导致未经身份验证的用户在某些情况下创建或修改超出预期范围的实例数据,造成权限提升。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| ServiceNow | ServiceNow AI Platform | < Xanadu Patch 11 Hot Fix 7a |
affected |
< Yokohama Patch 12 Hot Fix 3b |
affected | ||
< Yokohama Patch 13 Hot Fix 4 |
affected | ||
< Zurich Patch 7b Hot Fix 3 |
affected | ||
< Zurich Patch 8 Hot Fix 5 |
affected | ||
< Zurich Patch 9 Hot Fix 6 |
affected | ||
< Zurich Patch 10 Hot Fix 2m (m-branch) |
affected | ||
< Zurich Patch 10 Hot Fix 3 (standard) |
affected | ||
| … +7 more rows | |||
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| ServiceNow | ServiceNow AI Platform | 0 ~ Xanadu Patch 11 Hot Fix 7a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-74820 | 10.0 CRITICAL | Unauthenticated SQL Injection via Dynamic Schema ORDER BY Clause |
| CVE-2026-6876 | 10.0 CRITICAL | Sandbox Escape in ServiceNow AI Platform |
| CVE-2026-18885 | 10.0 CRITICAL | Unauthenticated Remote Code Execution in GraphQL Composite Data API |
No comments yet