Executive Summary
In early June 2026, ServiceNow identified a security vulnerability within its REST API that permitted unauthenticated users to access customer instance data. The flaw, present in the ‘Australia’ platform release and certain earlier versions with specific configurations, allowed unauthorized queries to sensitive data, including IT support tickets and employee records. ServiceNow applied a security update on June 5, 2026, to rectify the issue and notified affected customers directly. The incident underscores the critical importance of robust access controls and timely vulnerability management in cloud-based platforms.
This event highlights the ongoing challenges in securing API endpoints against unauthorized access. As enterprises increasingly rely on cloud services for core operations, ensuring the integrity and confidentiality of data through stringent security measures becomes paramount. Organizations must remain vigilant, regularly audit their systems, and promptly address identified vulnerabilities to mitigate potential risks.
Why This Matters Now
The ServiceNow data exposure incident serves as a stark reminder of the vulnerabilities inherent in cloud-based platforms. With the rapid adoption of such services, ensuring robust security measures and prompt vulnerability management is crucial to protect sensitive enterprise data from unauthorized access.
Attack Path Analysis
An unauthenticated attacker exploited a misconfigured ServiceNow REST API endpoint to access sensitive customer data. The attacker then escalated privileges by leveraging the exposed data to gain deeper access within the ServiceNow instance. Subsequently, the attacker moved laterally within the cloud environment to identify and access additional resources. They established a command and control channel to maintain persistent access and control over the compromised environment. The attacker exfiltrated sensitive data from the ServiceNow instance to an external location. Finally, the attacker caused significant impact by disrupting services and potentially leaking sensitive information.
Kill Chain Progression
Initial Compromise
Description
An unauthenticated attacker exploited a misconfigured ServiceNow REST API endpoint to access sensitive customer data.
Related CVEs
CVE-2025-3648
CVSS 8.2A vulnerability in the ServiceNow Now Platform allows unauthorized data inference through range query requests under certain ACL configurations.
Affected Products:
ServiceNow Now Platform – Aspen
Exploit Status:
no public exploit
MITRE ATT&CK® Techniques
Exploit Public-Facing Application
Cloud Service Discovery
Data from Cloud Storage Object
Data from Information Repositories
Command and Scripting Interpreter: Cloud API
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Restrict access to system components and cardholder data
Control ID: 7.2.1
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Risk Management Framework
Control ID: Article 5
CISA ZTMM 2.0 – Identity and Access Management
Control ID: Pillar 1: Identity
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Information Technology/IT
ServiceNow cloud misconfigurations expose critical IT operations data through public APIs, affecting incident management, asset tracking, and service catalogs across enterprise environments.
Health Care / Life Sciences
Public ServiceNow exposure risks HIPAA-protected patient data through misconfigured portals, threatening compliance with healthcare privacy regulations and patient information security requirements.
Financial Services
Banking institutions using ServiceNow face regulatory compliance violations and customer data exposure through unauthenticated API access to sensitive financial operational records.
Government Administration
Government ServiceNow instances risk exposing sensitive administrative data, citizen information, and internal operations through misconfigured public widgets and table APIs.
Sources
- Introducing snowpick: Testing ServiceNow for Public Data Exposurehttps://bishopfox.com/blog/introducing-snowpick-testing-servicenow-for-public-data-exposureVerified
- ServiceNow tells customers a bug left some of their data exposed to the internethttps://techcrunch.com/2026/06/10/servicenow-tells-customers-a-bug-left-some-of-their-data-exposed-to-the-internet/Verified
- CVE-2025-3648: ServiceNow Platform Information Disclosurehttps://www.sentinelone.com/vulnerability-database/cve-2025-3648/Verified
- ServiceNow's Secret Advisory Left Enterprises Unaware Their IT Data Was Exposedhttps://www.gblock.app/articles/servicenow-kb3067321-zero-auth-api-breach-june-2026Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF is pertinent to this incident as it could have limited the attacker's ability to move laterally and exfiltrate data by enforcing strict segmentation and identity-based access controls.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: The attacker's ability to exploit the misconfigured API endpoint could have been constrained, reducing unauthorized access to sensitive data.
Control: Zero Trust Segmentation
Mitigation: The attacker's ability to escalate privileges within the ServiceNow instance could have been limited, reducing unauthorized access to critical systems.
Control: East-West Traffic Security
Mitigation: The attacker's lateral movement within the cloud environment could have been constrained, reducing the risk of accessing additional resources.
Control: Multicloud Visibility & Control
Mitigation: The attacker's ability to establish and maintain command and control channels could have been limited, reducing persistent access to the environment.
Control: Egress Security & Policy Enforcement
Mitigation: The attacker's ability to exfiltrate sensitive data to external locations could have been constrained, reducing data loss.
The overall impact of the attack could have been limited, reducing service disruptions and data leakage.
Impact at a Glance
Affected Business Functions
- IT Service Management
- Human Resources
- Customer Service
Estimated downtime: 3 days
Estimated loss: $500,000
Unauthorized access to sensitive enterprise data, including IT support tickets, employee records, and internal documentation.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to enforce least privilege access and prevent unauthorized lateral movement.
- • Deploy Egress Security & Policy Enforcement to monitor and control outbound traffic, mitigating data exfiltration risks.
- • Utilize Multicloud Visibility & Control to gain comprehensive insights into cloud environments and detect anomalous activities.
- • Apply Inline IPS (Suricata) to identify and block known exploit patterns and malicious payloads.
- • Regularly review and update access control lists (ACLs) to ensure proper authentication and authorization mechanisms are in place.



