CVE-2026-13016

Severity CVSS v4.0:
CRITICAL
Type:
CWE-89 SQL Injection
Publication date:
24/09/2026
Last modified:
24/09/2026

Description

ServiceNow has remediated a SQL injection vulnerability that was identified in the ServiceNow AI Platform. This vulnerability could enable an unauthenticated user, in certain circumstances, to execute arbitrary SQL statements against the instance&amp;#39;s underlying database and gain access to, or modify, instance data beyond what was intended. <br /> <br /> <br /> <br /> <br /> <br /> ServiceNow deployed a security update to hosted instances and ServiceNow provided the update to our partners and self-hosted customers. We are not currently aware of malicious exploitation against ServiceNow instances. We recommend customers promptly apply appropriate updates or upgrade to a patched release if they have not already done so.