{"data":{"id":"57553c76-e31f-4bfb-b684-b72821f581b2","title":"CVE-2026-13016: ServiceNow has remediated a SQL injection vulnerability that was identified in the ServiceNow AI Platform. This vulnerab","summary":"ServiceNow fixed a SQL injection vulnerability (a flaw that lets attackers run unauthorized database commands) in its AI Platform that could have allowed unauthenticated users to access or change data in the system. The company has already deployed security updates to its hosted instances and made updates available to partners and self-hosted customers, with no known malicious attacks reported so far.","solution":"ServiceNow deployed a security update to hosted instances and provided the update to partners and self-hosted customers. The company recommends that customers promptly apply appropriate updates or upgrade to a patched release if they have not already done so.","labels":["security"],"sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-13016","publishedAt":"2026-09-24T19:17:11.820Z","cveId":"CVE-2026-13016","cweIds":["CWE-89"],"cvssScore":null,"cvssSeverity":null,"severity":"high","attackType":["other"],"issueType":"vulnerability","affectedPackages":null,"affectedVendors":[],"affectedVendorsRaw":["ServiceNow","ServiceNow AI Platform"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":"unknown","epssScore":0,"patchAvailable":null,"disclosureDate":"2026-09-24T19:17:11.820Z","capecIds":["CAPEC-66"],"crossRefCount":0,"attackSophistication":"moderate","impactType":["confidentiality","integrity"],"aiComponentTargeted":"inference","llmSpecific":false,"classifierConfidence":0.75,"researchCategory":null,"atlasIds":null}}