$ techbeacon▋
CVE & Exploits

Critical ServiceNow AI Platform Flaws Expose Data and Enable Remote Code Execution

Critical ServiceNow AI Platform Flaws Expose Data and Enable Remote Code Execution

ServiceNow, the cloud‑based workflow and IT service management provider, has disclosed a set of five security weaknesses in its AI Platform, two of which are rated critical. The vulnerabilities could let unauthenticated attackers run arbitrary SQL commands against the platform's backend database, retrieve confidential instance data, alter records and potentially elevate their privileges within a compromised environment.

The advisory, first reported by the security research group GBHackers, details that the flaws stem from insufficient input validation and overly permissive API endpoints. In the most severe cases, an attacker can craft a request that bypasses authentication altogether, inject malicious SQL, and extract or modify data stored in ServiceNow's relational tables. Because the AI Platform is tightly integrated with core ServiceNow services, the impact can cascade to broader enterprise workflows that rely on the system for ticketing, asset tracking and automation.

ServiceNow confirmed the findings and has already issued patches for all five vulnerabilities. The company urges all customers to apply the updates immediately, noting that the fixes address the input‑validation logic and tighten access controls on the affected APIs. For organizations unable to patch right away, ServiceNow recommends disabling the AI Platform features that expose the vulnerable endpoints and reviewing audit logs for any signs of unauthorized activity.

Industry analysts say the disclosure underscores the growing risk landscape surrounding AI‑driven SaaS applications. As enterprises embed machine‑learning services into critical business processes, any weakness in the underlying data handling can become a vector for large‑scale data breaches. The ServiceNow incident also highlights the importance of rigorous third‑party security testing; GBHackers' report demonstrates how external researchers continue to play a vital role in uncovering hidden flaws before they are exploited in the wild.

Looking ahead, ServiceNow plans to strengthen its vulnerability‑management program and accelerate security reviews for new AI features. The company has pledged to work with its security partners to conduct regular penetration testing and to provide clearer guidance to customers on secure configuration. Meanwhile, security teams across industries are advised to monitor for any anomalous queries or data access patterns that could indicate attempts to leverage the disclosed weaknesses before the patches are fully deployed.

Source: GBHackers
Vikas Thakur — Vikas covers DDoS attacks, botnet infrastructure, and network-layer threats. Hands-on experience with mitigation and traffic analysis, covers IoT botnets and infra-level attacks.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related