ServiceNow confirmed that attackers exploited an unauthenticated API endpoint to access customer instance data in early June 2026. Per Rescana and BleepingComputer, the vulnerable API had authentication disabled, allowing unauthenticated HTTP requests to query sensitive data from customer instances. ServiceNow deployed a fix on June 5 and a variant fix on June 10.
This is the third major ServiceNow vulnerability in eight months, following CVE-2025-12420 and CVE-2026-0542. Unlike the prior two, this flaw was actively exploited before the patch was deployed. ServiceNow later attributed the activity to security researchers, but the timeline raises questions about patch response time.
Key takeaways
- Attackers exploited an unauthenticated ServiceNow API endpoint between June 2-3, 2026.
- The flaw was in a Scripted REST Resource with authentication disabled.
- ServiceNow patched hosted instances on June 5 (initial) and June 10 (variant).
- Third major vulnerability in eight months, first with confirmed exploitation.
- No CVE assigned yet. ServiceNow notified affected customers via KB3067321.
Affected
Unauthenticated API Endpoint Exposes Customer Data
ServiceNow confirmed that attackers exploited an unauthenticated API endpoint to access customer instance data in early June 2026. Per Rescana, the vulnerable endpoint was configured with authentication disabled, allowing unauthenticated HTTP requests to query sensitive data from customer instances.
Per Rescana, ServiceNow received a bug bounty submission on April 22, 2026. Exploitation occurred between June 2-3. ServiceNow deployed a security update on June 5 and a second variant fix on June 10. The flaw primarily affects the Australia platform release and older releases with certain configuration changes.
First Confirmed Exploitation Among Three Recent Flaws
Unlike CVE-2025-12420 and CVE-2026-0542 (patched before exploitation), this flaw was actively exploited. Per CryptoBriefing, this is the third major ServiceNow vulnerability in eight months. ServiceNow instances store IT support tickets, employee records, and internal documentation. No CVE has been assigned; ServiceNow is evaluating publication.
Australia Platform Release Affected
Customers on the Australia platform release and those with certain configuration changes on older releases. Hosted instances were patched automatically. Review access logs for unexpected API calls. Per ServiceNow, affected customers were notified via KB3067321.
Timeline
Impact & actions
Unauthenticated API flaw allowed querying customer instance tables. Third major ServiceNow vulnerability in eight months. First with confirmed exploitation.
Security: Unauthenticated access to customer instance tables. Potential exposure of IT tickets, employee records, and internal documentation.
Recommended actions · High urgency
- 1Review access logs for unauthenticated API calls to related_list_edit endpoint.
- 2Verify all Scripted REST Resources require authentication.
- 3Contact ServiceNow support if your instance may be affected.
Technical details
- Exploitation
- Exploited in the wild
- Attack vector
- Network (unauthenticated HTTP requests to API endpoint)
Mitigations
- Hosted instances patched automatically.
- Verify authentication on all Scripted REST Resources.
- Review access logs for unauthenticated API calls.
Response
Vendor
FAQ
What happened with the ServiceNow API flaw?
Attackers exploited a ServiceNow API endpoint that had authentication disabled, allowing unauthenticated queries to customer instance tables containing IT tickets, employee records, and internal documentation.
Am I affected?
Customers on the Australia platform release and those who made certain configuration changes on older releases. Hosted instances were patched automatically on June 5 and June 10.
Were the attackers malicious or researchers?
Per CyberSecGuru, ServiceNow later said the activity appeared to be from security researchers in responsible disclosure, not threat actors. However, the exploitation occurred before the patch was applied.
What should I do now?
Review access logs for unexpected API calls. Verify authentication is enforced on all Scripted REST Resources. Subscribe to KB3067321 for updates.
The bottom line
ServiceNow patched an unauthenticated API flaw on June 5, 2026, after attackers queried customer instance tables between June 2-3. The root cause was a Scripted REST Resource with authentication disabled. Hosted instances were patched automatically. This is the third major ServiceNow vulnerability in eight months.
What happens next
What to do






