discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.

ServiceNow discloses security incident exposing customer data

ServiceNow says attackers used an unauthenticated API flaw to query customer instance data before a June 5 fix. It is notifying affected customers and weighing a CVE.

By Lawrence Abrams·Jun 9·bleepingcomputer.com·2 min read

Intelligence analysis by GPT-5.4 Mini

ServiceNow discloses security incident exposing customer data
Image: bleepingcomputer.com

ServiceNow disclosed a security incident after attackers exploited an unauthenticated access flaw in a vulnerable API endpoint. The company says it patched hosted instances on June 5 and is now warning impacted customers whose instances may have been queried.

Why it matters

ServiceNow sits inside a lot of enterprise workflows, so exposure in its customer instances can affect tickets, records, credentials, and internal operational details. The incident also shows how a single misconfigured or weakly protected API endpoint can become a broad customer-data problem.

ServiceNow found a locked door in one of its systems that was letting the wrong people peek inside. It fixed the door and is now telling customers to check whether anyone looked at their files, like a company checking who got into a file cabinet.

Analysis

What happened

ServiceNow says it found anomalous activity tied to a security issue that let an unauthenticated user, in some circumstances, gain more access than intended. The company says it pushed a security update to hosted customer instances on June 5, 2026, and that the update changed the API endpoint configuration so only authenticated users can access it.

According to the article, ServiceNow has confirmed that attackers exploited the flaw and successfully queried tables in customer instances. The company did not say what specific data was accessed, but customer instances can hold sensitive material such as IT support tickets, employee records, internal documents, asset inventories, incident reports, workflow data, and system configuration details.

Who is affected

ServiceNow told customers through support bulletins and direct support cases, but the bulletin is hidden behind its support login portal. The company says customers who did not receive a support case are not believed to be affected.

The bulletin says the issue mainly affects customers on the Australia platform release, or customers on older releases who made certain configuration changes before that release.

Clues from administrators

The article says administrators discussing the incident on Reddit believe the problem is tied to the REST endpoint /api/now/related_list_edit/create. One commenter claimed that endpoint had requires_authentication=false, and that the Friday update changed it to true. Admins also shared possible indicators of compromise, including requests from IP address 51.159.98.241.

What ServiceNow is advising

ServiceNow is still evaluating whether to publish a CVE. In the meantime, administrators are told to review logs for requests to /api/now/related_list_edit, check for activity from the listed IP, review exposed tickets and records for sensitive information, rotate any credentials or tokens shared through support workflows, and make sure API logging is enabled.

Key points

  • ServiceNow says attackers exploited an unauthenticated API flaw to query data from customer instances.
  • The company applied a security update on June 5, 2026, and says the fix limits access to authenticated users.
  • ServiceNow has not disclosed what data was accessed, but customer instances can contain sensitive enterprise records.
  • The issue appears to affect Australia release customers and some older releases with certain configuration changes.
  • Administrators are being told to review logs, investigate requests to the vulnerable endpoint, and rotate exposed credentials or tokens.
The Upside

If the patch and customer notifications work as intended, affected organizations can quickly check logs, limit exposure, and rotate anything sensitive that may have been shared through support workflows. ServiceNow’s review may also lead to a CVE, which would give defenders a clearer public handle on the issue.

The Downside

If attackers had time to query meaningful tables, organizations may need to treat the incident as a data-exposure event even without a public list of stolen records. The lack of disclosed technical detail also leaves some customers dependent on support cases and log review to know whether they were hit.

Originally reported at

bleepingcomputer.com

Discernion covers the story. Read the full piece at the source.

Tagssecuritybusinesstech

Author

Lawrence Abrams

Intelligence analysis by

GPT-5.4 Mini

Published

Jun 9, 2026

Source

bleepingcomputer.com

Share

Topics

securitybusinesstech

Related

More from this desk

Jul 29·thehackernews.com

Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory

A maximum-severity security flaw in Ruflo, an open-source agent meta-harness for Anthropic Claude Code and OpenAI Codex, allows unauthenticated remote code execution. The vulnerability, tracked as CVE-2026-59726, impacts all versions of the project before version 3.16.3.

Jul 29·thehackernews.com

Three Critical VMware Flaws Allow Auth Bypass, Code Execution, and VM Escape

Broadcom patched three critical VMware vulnerabilities including two CVSS 9.8 flaws in vCenter for auth bypass and arbitrary code execution, plus a VMXNET3 flaw enabling VM escape.

Jul 29·bleepingcomputer.com

Hackers target over 30 Minnesota water utilities in coordinated OT attack

Hackers targeted over 30 Minnesota water utilities in a coordinated cyberattack, disrupting operational technology systems. The Minnesota IT Services agency is working with federal and state partners to investigate and fortify the security of the state's critical infrastr…

Jul 29·bleepingcomputer.com

Your AI Agents Are Guessing at Scale: Permissions Decide the Damage

AI agents are designed to improvise, but this can lead to security risks when paired with broad access. Teams struggle to apply least privilege to agents, and traditional security models break down. Token Security offers a solution to discover and map risky access, and au…