# ServiceNow Security Incident Exposes Customer Data Through Unauthenticated API Flaw
ServiceNow, the enterprise software platform managing IT operations, HR workflows, and critical business processes for thousands of organizations worldwide, has disclosed a significant security incident stemming from an unauthenticated API endpoint vulnerability. The flaw allowed attackers to query and access sensitive customer instance data without valid credentials, compromising information including support tickets, employee records, credentials, API tokens, and internal documentation.
The company applied a security update to hosted customer instances on June 5, 2026, after detecting anomalous activity exploiting the vulnerability. ServiceNow has notified affected customers through private support bulletins rather than public disclosure, raising questions about the scope and severity of the breach.
## The Threat
On June 5, 2026, ServiceNow deployed a security patch to address what the company describes as "a security issue that could allow an unauthenticated user, in certain circumstances, to gain greater access to ServiceNow instances than intended." The vulnerability stemmed from improper API endpoint configuration that exposed authenticated resources to unauthenticated requests.
According to ServiceNow administrators discussing the incident on public forums, the vulnerable endpoint is located at /api/now/related_list_edit/create. The critical misconfiguration was the parameter requires_authentication=false, which allowed any attacker to make requests to this endpoint without providing valid credentials or session tokens. The security update changed this setting to requires_authentication=true, effectively closing the exploit path.
System administrators have identified indicators of compromise, with multiple reports of suspicious API requests originating from the IP address 51.159.98.241. These requests specifically targeted the vulnerable endpoint, suggesting attackers were actively exploiting the flaw to extract data from affected instances.
## Background and Context
ServiceNow is a critical enterprise platform used by over 8,000 organizations globally, managing operations across IT service management (ITSM), human resources, financial services, customer service management, and security operations. The platform acts as a central repository for enterprise workflow data, making it an attractive target for threat actors seeking to compromise entire organizations through a single breach.
The vulnerability affects customers running the Australia platform release or those on older releases who applied certain custom configuration changes to their instances. This suggests the flaw may have existed for an extended period, particularly impacting organizations with non-standard deployments or those on legacy versions.
ServiceNow's quiet notification approach—using a support portal bulletin rather than public disclosure—has drawn criticism from security researchers. The company initially stated it is "still evaluating whether it will publish a CVE" for the issue, meaning enterprises may not have formal vulnerability tracking for remediation purposes.
## Technical Details
The vulnerability centers on REST API endpoint misconfiguration, a common but potentially devastating security flaw. The /api/now/related_list_edit/create endpoint was designed to handle data modifications within ServiceNow instances but was incorrectly configured to permit unauthenticated access.
How the Attack Works:
| Stage | Description |
|-------|-------------|
| Discovery | Attackers identify the API endpoint through instance enumeration or public documentation |
| Exploitation | Attackers craft HTTP requests to the endpoint without authentication headers or tokens |
| Data Extraction | The misconfigured endpoint returns data from database tables that should require authentication |
| Escalation | Attackers systematically query multiple tables to access sensitive information |
API endpoint misconfiguration is particularly dangerous because:
## What Was Exposed
ServiceNow instances typically store highly sensitive enterprise data. While the company has not disclosed specific types of data accessed during the attacks, support tickets and related lists commonly contain:
This information represents a complete blueprint for attackers to understand an organization's infrastructure, identify secondary targets, and craft targeted attacks.
## Implications for Organizations
Immediate Risk:
Organizations using affected ServiceNow instances face credential compromise as a critical concern. If support tickets shared passwords, API tokens, or SSH keys during troubleshooting—a common practice—attackers now possess valid authentication credentials for downstream systems. This transforms a single API vulnerability into a multi-system breach.
Supply Chain Exposure:
ServiceNow data often includes information about third-party vendors, integration partners, and external service providers. An attacker with access to this information can identify and attack these connected organizations, creating a supply chain risk for ServiceNow customers' entire business ecosystem.
Regulatory Compliance:
Organizations in regulated industries (healthcare, finance, government) may face compliance violations and notification obligations if personal data was accessed. GDPR, HIPAA, and industry-specific frameworks require notification within specific timeframes, yet ServiceNow's quiet approach may have delayed discovery and reporting.
## Recommendations
For Immediate Action:
/api/now/related_list_edit endpoints, particularly from the IP address 51.159.98.241 or other suspicious sourcesrequires_authentication=true is set on all API endpointsFor Security Teams:
For Long-Term Prevention:
---
## HackWire Analysis
This incident exemplifies a troubling pattern in enterprise software security: critical vulnerabilities hidden behind quiet support bulletins while defenders race to patch blind. ServiceNow's decision to defer public disclosure—still evaluating whether a CVE is warranted—treats this as an internal matter despite affecting thousands of organizations globally.
What's particularly concerning is the vulnerability's nature. Authentication bypass at the API layer isn't a subtle edge case; it's a fundamental security control failure. The fact that requires_authentication=false existed in a production endpoint suggests inadequate security code review practices or a dangerous pattern of relaxing security constraints to "make things work."
The targeting of support tickets deserves special attention. This shift toward stealing operational intelligence rather than just customer data represents attackers' sophisticated understanding of enterprise IT. A support ticket containing a database connection string is more valuable than 10,000 customer email addresses—it's a direct path into the organization's crown jewels.
Organizations should assume their compromise window is unknown. The flaw may have existed for months. Threat actors with access to ServiceNow support tickets have effectively been handed a reconnaissance briefing: infrastructure layout, known vulnerabilities your own teams documented, vendor relationships, and shared secrets. The breach doesn't end with the patch; it begins there, as security teams struggle to determine what was accessed and whether attackers leveraged that access.
ServiceNow's eventual public disclosure of technical indicators (the IP address, endpoint name, configuration details) was only forced by community detection on Reddit. Enterprises deserve better than crowdsourced vulnerability attribution.
— HackWire Editorial
---
## Related Coverage