Skip to content

ServiceNow

Disclosed Jun 9, 20263 months agoUnverified

ServiceNow unauthenticated API flaw exposed customer instance data

ServiceNow notified impacted customers that an API endpoint set not to require authentication allowed access to instance data such as support tickets, employee records and configuration details. It patched the endpoint on June 5, weeks after a similar bug bounty report, and later suggested researchers rather than criminals were involved.

What is known

People affectedNot stated in the sources we have
DisclosedJun 9, 2026
DiscoveredJun 2026
AttackExposed data
Data exposedInternal documents, Employment, Messages
SectorTech · US
StatusUnverified: not yet confirmed by an official notice, a filing or the organization

Sources

Source
ServiceNow discloses security incident exposing customer datableepingcomputer.com · News

Notices filed

WhereFiledPeople
ResearchtotalJun 9
History of this record
  • 2026-09-25 · added · seed source

First seen 2026-09-25 (Research). Record counts are as reported. Not legal advice.

Everything about ServiceNow

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.