ServiceNow Data Breach Exposes Customer Data via API Vulnerability

ServiceNow Data Breach Exposes Customer Data via API Vulnerability

First seen 10 Jun 2026, 12:11 UTC BleepingcomputerCybernewsCryptobriefingTechcrunchCybersecuritynews+13 87% similarity 69.8

Article Content

Browse articles
ThreatCluster

ServiceNow confirmed a data breach on June 9, 2026, after attackers exploited an unauthenticated API endpoint, allowing access to sensitive customer data. The vulnerability, found in the endpoint '/api/now/related_list_edit/create', was due to a misconfiguration that set the 'requires_authentication' parameter to false. This flaw allowed unauthorized users to query customer instance tables without valid credentials. The breach was detected between June 2 and June 3, 2026, and ServiceNow applied a patch on June 5, 2026, to secure the affected instances. Customers primarily on the Australia platform release or with specific configuration changes were impacted. Evidence suggests that attackers successfully accessed sensitive data, including IT support tickets and employee records. ServiceNow has begun notifying affected customers through support cases, but the full extent of the data accessed remains unclear. This incident marks the third significant authentication-related vulnerability for ServiceNow in eight months.

Key Points: • ServiceNow's API vulnerability allowed unauthorized access to sensitive customer data. • The breach was detected on June 2-3, 2026, and a patch was applied on June 5, 2026. • Affected customers include those on the Australia platform release and those with specific configurations.

ThreatCluster AI

Timeline

2026-01-12
CVE-2025-12420 published
ServiceNow patched a vulnerability allowing unauthenticated user impersonation, marking a trend of authentication-related issues.
N/A
2026-02-25
CVE-2026-0542 published
ServiceNow disclosed another vulnerability involving remote code execution threats, highlighting ongoing security challenges.
N/A
2026-06-02
Unauthorized access detected
ServiceNow identified anomalous activity indicating unauthorized queries against customer instances.
Techtimes
2026-06-03
Exploitation confirmed
Attackers successfully exploited the unauthenticated API flaw to access customer data.
Bleepingcomputer
2026-06-05
Security patch applied
ServiceNow applied a security update to mitigate the vulnerability by requiring authentication for the affected API endpoint.
Rescana
2026-06-09
Breach disclosed
ServiceNow confirmed the data breach and began notifying affected customers through support cases.
Cybernews

Community

Browse all →