---
title: 「ServiceNow AI Platform」发现多项SQL注入等安全漏洞
url: https://www.dataloco.com/zh/servicenow-ai-platformsql
published: 2026-09-28T01:26:01+00:00
language: zh
section: 安全
source: https://www.security-next.com/190682
organizations: servicenow, sqli
publisher: Dataloco
---

# 「ServiceNow AI Platform」发现多项SQL注入等安全漏洞

「ServiceNow AI Platform」上发现了五项安全漏洞，其中包括多个被认为是严重的漏洞。ServiceNow已呼吁用户进行更新。

该公司于2026年9月24日发布了安全咨询，公开了基于CVE的五项漏洞。这些漏洞是通过内部安全测试、协作报告和漏洞奖励计划被识别出来的。

「CVE-2026-13016」是一个在特定环境下可以被未经认证的网络攻击者利用的SQL注入漏洞，允许对实例中的数据库进行访问和篡改。

而「CVE-2026-86860」则是由于授权处理不当导致的漏洞，攻击者可以在未认证的情况下从实例中提取数据，并实现权限提升。

这两项漏洞的通用漏洞评分系统「CVSSv4.0」基础分均为「9.3」，被评定为「严重（Critical）」。

## This story in other languages

- [العربية](https://www.dataloco.com/ar/aktshaf-aad-thghrat-fy-mns-servicenow-ai)
- [Polski](https://www.dataloco.com/pl/wykryto-wiele-podatnosci-w-platformie-servicenow-ai)
- [Français](https://www.dataloco.com/fr/des-vulnerabilites-multiples-detectees-dans-la-plateforme-servicenow-ai)
- [Norsk](https://www.dataloco.com/no/servicenow-ai-plattform-har-flere-sarbarheter)
- [Deutsch](https://www.dataloco.com/de/servicenow-ai-plattform-weist-mehrere-sicherheitsanfalligkeiten-auf)
- [English](https://www.dataloco.com/en/multiple-vulnerabilities-discovered-in-servicenow-ai-platform)
