Cybernews
ServiceNow Data Breach Exposes Customer Data via API Vulnerability
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
ServiceNow confirmed a data breach on June 9, 2026, after attackers exploited an unauthenticated API endpoint, allowing access to sensitive customer data. The vulnerability, found in the endpoint '/api/now/related_list_edit/create', was due to a misconfiguration that set the 'requires_authentication' parameter to false. This flaw allowed unauthorized users to query customer instance tables without valid credentials. The breach was detected between June 2 and June 3, 2026, and ServiceNow applied a patch on June 5, 2026, to secure the affected instances. Customers primarily on the Australia platform release or with specific configuration changes were impacted. Evidence suggests that attackers successfully accessed sensitive data, including IT support tickets and employee records. ServiceNow has begun notifying affected customers through support cases, but the full extent of the data accessed remains unclear. This incident marks the third significant authentication-related vulnerability for ServiceNow in eight months.
Key Points: • ServiceNow's API vulnerability allowed unauthorized access to sensitive customer data. • The breach was detected on June 2-3, 2026, and a patch was applied on June 5, 2026. • Affected customers include those on the Australia platform release and those with specific configurations.