News

ServiceNow AI Platform exposes database to anonymous SQL

Louis Stowasser
Louis Stowasser
Tuesday 29 September 2026
ServiceNow AI Platform exposes database to anonymous SQL
ServiceNow AI Platform exposes database to anonymous SQL

CVE-2026-13016 is an unauthenticated SQL injection in ServiceNow AI Platform, the enterprise application platform underneath ServiceNow’s workflow, IT service management, HR, customer-service, security and low-code products. In the conditions ServiceNow has not publicly detailed, a remote attacker can cause the platform to execute arbitrary SQL against the instance’s underlying database.

That matters because SQL injection is not merely a malformed request or a limited application bug. The advisory says an attacker could access or modify instance data beyond what was intended. No account, role or prior foothold is required by the published rating; the attacker’s prerequisite is network reachability to a vulnerable instance and whatever unspecified circumstances make the flaw reachable.

The missing technical detail is itself important

ServiceNow’s September advisory groups this issue with other AI Platform fixes, but the public material does not name the vulnerable endpoint, request field, affected subcomponent or triggering sequence. Nor is there a public patch diff or source snippet showing the unsafe query construction. Teams should therefore resist assuming that a generic web-application firewall rule or input filter covers it.

The vendor credits Adam Kues of Assetnote, while the public CVE record describes the discovery method as unknown. That record also makes clear that this is not one universal build target: it lists separate fixed thresholds across Yokohama, Zurich and Australia release branches. Affected Yokohama systems need at least Patch 13 Hot Fix 5a. Zurich fixes include Patch 10 Hot Fix 3b, Patch 10 Hot Fix 4a W32, or Patch 11 Hot Fix 3 depending on branch; Australia fixes include Patch 2 Hot Fix 4b W32, Patch 4 Hot Fix 3, or Patch 5. The full version matrix is the reference to use rather than selecting the earliest-looking patch for a family. The public record does not confirm the status of older or unlisted release families.

No confirmed exploitation or usable public exploit

As of September 29, ServiceNow said it was not aware of malicious exploitation, and CISA’s enrichment recorded exploitation as none. CVE-2026-13016 was also absent from the Known Exploited Vulnerabilities catalogue. There are no confirmed incidents, threat actors, victims or indicators tied to this flaw in the supplied public material.

No public proof of concept has been confirmed. One tracker has an empty sightings table, while another claims five public repositories without naming or linking them; those claims could not be independently checked. Treat exploit availability as unconfirmed, not as evidence that exploitation is impossible.

Hosted customers should verify; self-hosted teams must act

ServiceNow says it deployed the update to hosted instances and supplied it to partners and self-hosted customers. Hosted customers should still obtain confirmation that their instance received the remediation. Partners and self-hosted operators should identify their precise release family and patch branch, apply the matching fixed build promptly, and document the result.

The exposure is concentrated wherever enterprises use ServiceNow to run business workflows: government, financial services, healthcare, manufacturing, telecoms, education and technology all commonly deploy it. Given the potential to read or alter the platform’s data, review database and platform audit logs for unexpected requests or data changes where logging permits, while recognizing that public reporting supplies no signature or endpoint to hunt.

For security teams, the practical task is straightforward: establish whether any self-managed or partner-operated ServiceNow instance is on an affected branch, then patch to its exact threshold instead of relying on a broad version label. SecAlerts monitors an organisation’s actual software stack and alerts on new vulnerabilities affecting the products it runs, which helps keep that inventory-to-remediation loop current.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203