Vulnerabilities · 96 days ago
An exposed ServiceNow API turns support records into a trust break, not just a data leak. If attackers could query instance tables without authentication, they may have pulled tickets, notes, and internal records that hold passwords, API tokens, and other secrets that still work after the portal is fixed.
ServiceNow says attackers exploited the flaw to query customer instance tables and that it applied a security update to hosted instances on June 5, 2026. The update changed the API so only authenticated users can access it, but the company has not disclosed what data was taken; support cases often carry the exact secrets teams share during troubleshooting.
That means the risk can extend into other accounts and services that trusted those records. A patched SaaS portal does not undo credentials or tokens already lifted from helpdesk data.
5 sources covering this story
Bug Bounty Research Triggers ServiceNow Security Alert
Bug bounty research inadvertently led organizations to believe they were being breached through their ServiceNow instances.
ServiceNow tells customers a bug left some of their data exposed to the internet | TechCrunch
ServiceNow is used by thousands of enterprises to automate their internal processes, but says several customers had data accessed because of a security bug.
ServiceNow Flaw Exploited to Gain Unauthorized Access to Customer Instances
A ServiceNow security issue allowed unauthenticated users, in certain circumstances, to gain greater access to susceptible instances than intended.
ServiceNow Patches Vulnerability Exploited Against Some Customers
The company updated hosted customer instances to patch a security issue it reportedly had known about since April 7.
ServiceNow discloses security incident exposing customer data
ServiceNow is warning about a security incident after attackers exploited an unauthenticated access flaw through a vulnerable API endpoint, allowing them to query data from customer instances.
Part of the PlainSec briefing for 2026-06-10