ServiceNow reveals security issue affecting customer data, but won't reveal much on what actually happened

https://cdn.mos.cms.futurecdn.net/sqGgDPxHyGtqunPo56h9cL-2560-80.jpg
  • ServiceNow fixes API flaw which let unauthenticated attackers query some customer instance tables
  • Issue mainly hit customers on the Australia release or older versions with custom configs
  • Admins urged to review logs for /api/now/related_list_edit requests, especially from 51.159.98.241

ServiceNow has told some of its customers that cybercriminals were able to abuse a flaw in an API endpoint in an attemtpy to access their data.

In a support bulletin published on its customer support portal, the company said it had addressed an issue, “that could allow an unauthenticated user, in certain circumstances, to gain greater access to ServiceNow instances than intended.”

A fix was applied on June 5 2026, the bulletin said, which changed the API endpoint configuration to limit access just to authenticated users.

Affecting Australians

The company said that the attackers exploited the vulnerability to query customer instance tables but did not say what type of data they were...

Copyright of this story solely belongs to techradar.com. To see the full text click HERE

Read more