ServiceNow tells customers a bug left some of their data exposed to the internet

https://techcrunch.com/wp-content/uploads/2024/06/GettyImages-1782807384.jpg?w=1024

7:13 AM PDT · June 10, 2026

Cloud technology giant ServiceNow appears to have notified some of its enterprise customers that a software bug on its platform was allowing anyone on the internet to access their data.

A knowledge base article, which ServiceNow has hidden behind a login wall but has been shared on Reddit, says the company on June 5 patched some customer instances to fix a bug that had allowed unauthenticated users to “gain greater access” to ServiceNow-hosted data than intended.

The bug allowed potentially anyone to obtain data stored in customer instances without requiring credentials, such as a password.

It’s not clear who had improper access to ServiceNow customers, what data was accessed or taken, or if any group was involved. Given that the security incident appears to stem from a data-exposing bug, it’s unclear if customers could have protected themselves from improper access.

ServiceNow...

Copyright of this story solely belongs to techcrunch.com. To see the full text click HERE

Read more