CVE-2026-13016
Severity CVSS v4.0:
CRITICAL
Type:
CWE-89
SQL Injection
Publication date:
24/09/2026
Last modified:
24/09/2026
Description
ServiceNow has remediated a SQL injection vulnerability that was identified in the ServiceNow AI Platform. This vulnerability could enable an unauthenticated user, in certain circumstances, to execute arbitrary SQL statements against the instance&#39;s underlying database and gain access to, or modify, instance data beyond what was intended. <br />
<br />
<br />
<br />
<br />
<br />
ServiceNow deployed a security update to hosted instances and ServiceNow provided the update to our partners and self-hosted customers. We are not currently aware of malicious exploitation against ServiceNow instances. We recommend customers promptly apply appropriate updates or upgrade to a patched release if they have not already done so.
Impact
Base Score 4.0
9.30
Severity 4.0
CRITICAL


