ServiceNow
Disclosed Jun 9, 20263 months agoUnverified
ServiceNow unauthenticated API flaw exposed customer instance data
ServiceNow notified impacted customers that an API endpoint set not to require authentication allowed access to instance data such as support tickets, employee records and configuration details. It patched the endpoint on June 5, weeks after a similar bug bounty report, and later suggested researchers rather than criminals were involved.
What is known
| People affected | Not stated in the sources we have |
|---|---|
| Disclosed | Jun 9, 2026 |
| Discovered | Jun 2026 |
| Attack | Exposed data |
| Data exposed | Internal documents, Employment, Messages |
| Sector | Tech · US |
| Status | Unverified: not yet confirmed by an official notice, a filing or the organization |
Sources
| Source | |
|---|---|
| ServiceNow discloses security incident exposing customer datableepingcomputer.com · News | News |
Notices filed
| Where | Filed | People |
|---|---|---|
| Researchtotal | Jun 9 |
History of this record
- 2026-09-25 · added · seed source
First seen 2026-09-25 (Research). Record counts are as reported. Not legal advice.