Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

ServiceNow — Vulnerabilities & Security Advisories 31

Browse all 31 CVE security advisories affecting ServiceNow. AI-powered Chinese analysis, POCs, and references for each vulnerability.

ServiceNow operates as a cloud-based platform primarily used for IT service management, automating workflows for incident, change, and problem management across enterprise environments. Its architecture, which integrates numerous modules and third-party integrations, has historically exposed it to diverse vulnerability classes. Recorded Common Vulnerabilities and Exposures (CVEs) frequently involve remote code execution, cross-site scripting, and privilege escalation flaws, often stemming from complex input validation failures or insecure direct object references within its web interface. While the platform employs robust encryption and access controls, its expansive attack surface presents significant risks if misconfigured. Notable security incidents have included data exfiltration attempts and unauthorized access due to weak authentication mechanisms, highlighting the critical importance of rigorous patch management and strict identity governance to mitigate potential exploitation of these systemic weaknesses.

CVE ID Title CVSS Severity Published
CVE-2026-86860 Unauthenticated Sensitive Data Disclosure in ServiceNow AI Platform — ServiceNow AI Platform 9.3 Critical 2026-09-24
CVE-2026-86859 Unauthenticated Arbitrary Record Disclosure in ServiceNow AI Platform — ServiceNow AI Platform 8.7 High 2026-09-24
CVE-2026-13016 Unauthenticated SQL Injection in ServiceNow AI Platform — ServiceNow AI Platform 9.3 Critical 2026-09-24
CVE-2026-86858 Unauthenticated Privilege Escalation via GraphQL in ServiceNow AI Platform — ServiceNow AI Platform 8.7 High 2026-09-24
CVE-2026-86857 Authorization Bypass in ServiceNow AI Platform — ServiceNow AI Platform 8.4 High 2026-09-24
CVE-2026-74820 Unauthenticated SQL Injection via Dynamic Schema ORDER BY Clause — ServiceNow AI Platform 10.0 Critical 2026-08-27
CVE-2026-18886 Unauthenticated Privilege Escalation via System Configuration Image Upload Processor — ServiceNow AI Platform 10.0 Critical 2026-08-27
CVE-2026-18885 Unauthenticated Remote Code Execution in GraphQL Composite Data API — ServiceNow AI Platform 10.0 Critical 2026-08-27
CVE-2026-6876 Sandbox Escape in ServiceNow AI Platform — ServiceNow AI Platform 10.0 Critical 2026-08-27
CVE-2026-6875 Sandbox Escape in ServiceNow AI Platform — ServiceNow AI Platform 9.5 Critical 2026-07-13
CVE-2026-0542 Remote Code Execution in ServiceNow AI Platform — ServiceNow AI Platform CWE-653 9.8AI Critical AI 2026-02-25
CVE-2025-12420 Unauthenticated Privilege Escalation in ServiceNow AI Platform — Now Assist AI Agents CWE-250 9.8AI Critical AI 2026-01-12
CVE-2025-11449 Reflected Cross Site Scripting in ServiceNow AI Platform — ServiceNow AI Platform CWE-79 6.1AI Medium AI 2025-10-10
CVE-2025-11450 Reflected Cross Site Scripting in ServiceNow AI Platform — ServiceNow AI Platform CWE-79 6.1AI Medium AI 2025-10-10
CVE-2025-3089 Broken Access Control in ServiceNow AI Platform — ServiceNow AI Platform CWE-639 6.5AI Medium AI 2025-08-12
CVE-2025-3648 Data Inference in Now Platform via Conditional ACLs — Now Platform CWE-1220 5.3AI Medium AI 2025-07-08
CVE-2025-0337 Authorization bypass in Now Platform — Now Platform CWE-639 6.5 Medium 2025-03-06
CVE-2024-5890 HTML Injection in the Assessment plugin — Now Platform CWE-79 4.3 Medium 2024-12-02
CVE-2024-8924 Unauthenticated Blind SQL Injection in Core Platform — Now Platform CWE-89 7.5 High 2024-10-29
CVE-2024-8923 Sandbox Escape in Now Platform — Now Platform CWE-94 9.8 Critical 2024-10-29
CVE-2024-5217 Incomplete Input Validation in GlideExpression Script — Now Platform CWE-184 9.8 Critical 2024-07-10
CVE-2024-5178 Incomplete Input Validation in SecurelyAccess API — Now Platform CWE-184 4.9 Medium 2024-07-10
CVE-2024-4879 Jelly Template Injection Vulnerability in ServiceNow UI Macros — Now Platform CWE-1287 9.8 Critical 2024-07-10
CVE-2023-3442 Missing Authorization in Jenkins plug-in for ServiceNow DevOps — Jenkins plug-in for ServiceNow DevOps CWE-862 7.7 High 2023-07-26
CVE-2023-3414 Cross-Site Request Forgery (CSRF) in Jenkins Plug-in for ServiceNow DevOps — Jenkins plug-in for ServiceNow DevOps CWE-352 6.1 Medium 2023-07-26
CVE-2023-1298 ServiceNow 跨站脚本漏洞 — Now User Experience CWE-79 4.3 Medium 2023-07-06
CVE-2022-43684 ACL bypass in Reporting functionality — Now Platform CWE-200 9.9 Critical 2023-06-13
CVE-2023-1209 ServiceNow 跨站脚本漏洞 — ServiceNow Records CWE-79 4.3 Medium 2023-05-23
CVE-2022-46389 Cross-Site Scripting (XSS) vulnerability found on logout functionality — Now Platform CWE-79 6.1 Medium 2023-04-17
CVE-2022-46886 ServiceNow 输入验证错误漏洞 — ServiceNow 5.5 Medium 2023-04-14

This page lists every published CVE security advisory associated with ServiceNow. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.