[WID-SEC-2026-2302] ServiceNow AI Platform: Schwachstelle ermöglicht Codeausführung CVSS Base Score 9.0 (kritisch) CVSS Temporal Score 7.8 (hoch) Remoteangriff ja Datum 13.07.2026 Stand 14.07.2026 Mitigation ja Betroffene Systeme Betriebssystem Sonstiges Produktbeschreibung Die ServiceNow AI Platform ist eine Sammlung von KI-gestützten Funktionen, die in die ServiceNow-Plattform integriert sind, um Arbeitsabläufe zu automatisieren und Entscheidungen zu verbessern. Produkte 13.07.2026 ServiceNow AI Platform <Brazil EA ServiceNow AI Platform <Brazil GA ServiceNow AI Platform <Australia Patch 2 ServiceNow AI Platform <Zurich Patch 7b ServiceNow AI Platform <Zurich Patch 9 ServiceNow AI Platform <Yokohama Patch 12 Hot Fix 1b ServiceNow AI Platform <Yokohama Patch 13 Angriff Angriff Ein entfernter, anonymer Angreifer kann eine Schwachstelle in ServiceNow AI Platform ausnutzen, um beliebigen Programmcode auszuführen. CVE Informationen Versionshistorie Feedback zum Advisory geben
A critical vulnerability (CVSS Base Score 9.0) in the ServiceNow AI Platform allows an unauthenticated remote attacker to execute arbitrary code. Affected versions include all releases prior to Brazil EA, Brazil GA, Australia Patch 2, Zurich Patch 7b, Zurich Patch 9, Yokohama Patch 12 Hot Fix 1b, and Yokohama Patch 13. A mitigation is available, though specific patch or workaround details are not provided in the advisory.