Security advisory
CybersecurityCriticalResolvedUpdated Jul 19, 2026

ServiceNow Patches Exploited API Flaw That Exposed Customer Data

ServiceNow confirmed attackers exploited an unauthenticated API endpoint to query customer instance data between June 2-3, 2026. Patched June 5. Third major ServiceNow vulnerability in eight months.

Emanuel De AlmeidaJun 6, 2026, 1:30 AM3 min read
Severity
Critical
Status
Resolved
Entity
ServiceNow
Confirmed by
ServiceNow (KB3067321), BleepingComputer, Rescana

ServiceNow confirmed that attackers exploited an unauthenticated API endpoint to access customer instance data in early June 2026. Per Rescana and BleepingComputer, the vulnerable API had authentication disabled, allowing unauthenticated HTTP requests to query sensitive data from customer instances. ServiceNow deployed a fix on June 5 and a variant fix on June 10.

This is the third major ServiceNow vulnerability in eight months, following CVE-2025-12420 and CVE-2026-0542. Unlike the prior two, this flaw was actively exploited before the patch was deployed. ServiceNow later attributed the activity to security researchers, but the timeline raises questions about patch response time.

Key takeaways

  • Attackers exploited an unauthenticated ServiceNow API endpoint between June 2-3, 2026.
  • The flaw was in a Scripted REST Resource with authentication disabled.
  • ServiceNow patched hosted instances on June 5 (initial) and June 10 (variant).
  • Third major vulnerability in eight months, first with confirmed exploitation.
  • No CVE assigned yet. ServiceNow notified affected customers via KB3067321.

Affected

Vendors
ServiceNow
Products
ServiceNow Platform (Australia release)

Unauthenticated API Endpoint Exposes Customer Data

ServiceNow confirmed that attackers exploited an unauthenticated API endpoint to access customer instance data in early June 2026. Per Rescana, the vulnerable endpoint was configured with authentication disabled, allowing unauthenticated HTTP requests to query sensitive data from customer instances.

Per Rescana, ServiceNow received a bug bounty submission on April 22, 2026. Exploitation occurred between June 2-3. ServiceNow deployed a security update on June 5 and a second variant fix on June 10. The flaw primarily affects the Australia platform release and older releases with certain configuration changes.

First Confirmed Exploitation Among Three Recent Flaws

Unlike CVE-2025-12420 and CVE-2026-0542 (patched before exploitation), this flaw was actively exploited. Per CryptoBriefing, this is the third major ServiceNow vulnerability in eight months. ServiceNow instances store IT support tickets, employee records, and internal documentation. No CVE has been assigned; ServiceNow is evaluating publication.

Australia Platform Release Affected

Customers on the Australia platform release and those with certain configuration changes on older releases. Hosted instances were patched automatically. Review access logs for unexpected API calls. Per ServiceNow, affected customers were notified via KB3067321.

Timeline

Apr 22, 2026
Bug bounty submission receivedServiceNow receives a bug bounty submission about the unauthenticated API endpoint, per Rescana.
Jun 2, 2026
Exploitation detectedExploitation begins. Anomalous activity detected on the unauthenticated API endpoint.
Jun 5, 2026
Initial patch deployedServiceNow deploys security update enforcing authentication on the vulnerable endpoint.
Jun 10, 2026
Variant fix appliedServiceNow applies second update for a variant of the vulnerability.
Jun 11, 2026
Attribution updatedServiceNow states activity appeared to be from security researchers in responsible disclosure.

Impact & actions

Unauthenticated API flaw allowed querying customer instance tables. Third major ServiceNow vulnerability in eight months. First with confirmed exploitation.

Security: Unauthenticated access to customer instance tables. Potential exposure of IT tickets, employee records, and internal documentation.

Recommended actions · High urgency

  1. 1Review access logs for unauthenticated API calls to related_list_edit endpoint.
  2. 2Verify all Scripted REST Resources require authentication.
  3. 3Contact ServiceNow support if your instance may be affected.

Technical details

Exploitation
Exploited in the wild
Attack vector
Network (unauthenticated HTTP requests to API endpoint)

Mitigations

  • Hosted instances patched automatically.
  • Verify authentication on all Scripted REST Resources.
  • Review access logs for unauthenticated API calls.

Response

Vendor

ServiceNow applied updates to hosted instances on June 5 and June 10. Affected customers notified via KB3067321.

FAQ

What happened with the ServiceNow API flaw?

Attackers exploited a ServiceNow API endpoint that had authentication disabled, allowing unauthenticated queries to customer instance tables containing IT tickets, employee records, and internal documentation.

Am I affected?

Customers on the Australia platform release and those who made certain configuration changes on older releases. Hosted instances were patched automatically on June 5 and June 10.

Were the attackers malicious or researchers?

Per CyberSecGuru, ServiceNow later said the activity appeared to be from security researchers in responsible disclosure, not threat actors. However, the exploitation occurred before the patch was applied.

What should I do now?

Review access logs for unexpected API calls. Verify authentication is enforced on all Scripted REST Resources. Subscribe to KB3067321 for updates.

The bottom line

ServiceNow patched an unauthenticated API flaw on June 5, 2026, after attackers queried customer instance tables between June 2-3. The root cause was a Scripted REST Resource with authentication disabled. Hosted instances were patched automatically. This is the third major ServiceNow vulnerability in eight months.

What happens next

ServiceNow is evaluating CVE publication. Further updates expected via KB3067321.

What to do

Review access logs for unauthenticated API calls. Verify all Scripted REST Resources require authentication. Subscribe to KB3067321.

Reader reviews

Rate this articleBe the first to rate
No written reviews yetRate the article above, or be the first to share your experience.

Related articles