ServiceNow Flaw Exploited to Gain Unauthorized Access to Customer Instances
ServiceNow says attackers exploited a flaw to get deeper unauthorized access to some customer instances. The company patched it on June 5 and notified impacted customers.
Intelligence analysis by GPT-5.4 Mini

ServiceNow says it found anomalous activity tied to a security issue that could let an unauthenticated user gain more access than intended in certain circumstances. The company patched hosted instances, notified affected customers, and said it saw evidence of successful table queries against a subset of customers.
ServiceNow found a door in its system that was easier to open than it should have been. Attackers may have slipped through and looked at some customer information, so the company fixed the door and warned the affected customers.
Analysis
What happened
ServiceNow says it identified a security issue that could, in certain circumstances, let an unauthenticated user gain greater access to ServiceNow instances than intended. The company applied a security update to hosted customer instances on June 5, 2026, and said the change tightens an endpoint configuration so only authenticated users can access it.
Scope and impact
The flaw does not yet have a CVE identifier. According to ServiceNow, the issue affects customers on the Australia platform release, as well as customers who made certain configuration changes on releases older than Australia. The company said it detected anomalous activity related to the issue and observed evidence of successful queries of instance tables against a subset of customers. Impacted customers have been notified.
How the story developed
The issue first surfaced on Reddit, where a user claimed their security team reported the vulnerability to ServiceNow and that the company had known about it internally since April 7, 2026. That claim is not independently confirmed in the article, but it helps explain why the problem began circulating before ServiceNow’s public advisory.
Why this stands out
The incident is notable because the weakness appears to sit at the access-control layer of a managed SaaS platform. When a tenant boundary is weakened, the downside is not limited to one customer workflow; it can expose data or metadata across affected instances if abuse succeeds. ServiceNow’s notice suggests it has already seen signs of exploitation, which makes the patching timeline and customer notification especially important.
Key points
- ServiceNow says unknown attackers exploited a flaw to gain greater access than intended.
- The company patched hosted customer instances on June 5, 2026.
- ServiceNow observed anomalous activity and successful queries against a subset of customers.
- The issue affects the Australia release and some older release configurations.
- The flaw has no CVE identifier yet.
The patch is already in place for hosted customer instances, which should reduce further abuse of the flaw. If customers follow the guidance and ServiceNow’s endpoint change works as intended, exposure should be contained to the affected subset.
The article says ServiceNow already saw evidence of successful queries against a subset of customers, so some data may have been exposed before the fix. Because the issue lacks a CVE and affects specific releases and configurations, some customers may not realize they were impacted until they review logs or receive a notice.



