Phone : +91 95 8290 7788 | Email : sales@itmonteur.net

Register & Request Quote | Submit Support Ticket

Home » Cyber Security News » Vulnerabilities & Exploits » ServiceNow data breach: Software bug exposed customer data to internet access

ServiceNow data breach: Software bug exposed customer data to internet access

ServiceNow data breach: Software bug exposed customer data to internet access

https://etimg.etb2bimg.com/thumb/msid-131675065,imgsize-2031894,width-1200,height=627,overlay-etciso,resizemode-75/data-breaches/servicenow-data-breach-software-bug-exposed-customer-data-to-internet-access.jpg

Cloud technology giant ServiceNow has notified some of its customers that a software bug on its platform was allowing anyone on the internet to access their data. According to a report in TechCrunch, a knowledge base article, which ServiceNow has hidden behind a login wall but has been shared on Reddit, says that the company on June 5 patched some customer instances to fix a bug that had allowed unauthenticated users to “gain greater access” to ServiceNow-hosted data than intended.

The bug is said to have allowed potentially anyone to access data stored in customer instances without requiring credentials, such as a password. On June 5, 2026, ServiceNow applied a security update that concerned a security issue that could allow an unauthenticated user, in certain circumstances, to gain greater access to ServiceNow instances than intended.

Here’s what the post on Reddit says about the data leak

According to a post on Reddit, ServiceNow told some users that “We have detected anomalous activity relating to the security issue. For a subset of customers, we have observed evidence of successful queries of instance tables. We have notified customers if successful queries were observed via case. If you have not received a case from us, then we did not observe such activity in connection with your instance and no action is currently required.”

It further said: “We have taken steps to provide this security update to partners and customers.” The post has also shared an FAQ published by the company.

Frequently Asked Questions

Q: Is my instance in scope of the security issue?

A: The security issue pertains to customers who are on the Australia platform release or made certain configuration changes to instances on releases prior to Australia.

Q: Will additional actions be required later?

A: If additional customer action is required, we will update this KB. Please subscribe to this KB to be informed of future updates.

Q: Will a CVE be published?

A: ServiceNow is currently evaluating publishing a CVE based on our internal policies and procedures. We will update this KB when we have more information to share.

How customers can check if their data has leaked

Similarly, Network defenders shared an IP address, 51.159.98.241, in a Reddit post and said that it is an indicator of potential data access if found in a customer’s logs.

A few things I’d recommend regardless of your release:

  • Hunt the IOC now: 51.159.98.241 is the confirmed source IP floating around this thread. If you have transaction logs, filter for that IP + the /api/now/related_list_edit path. Five hits seems to be typical for affected tenants.
  • Don’t trust the Guest user framing. The attacker showing up as Guest doesn’t mean a Guest account did anything – it just means the endpoint had no auth context to log against. Your alert rules probably aren’t tuned for that.
  • If you don’t have REST message logging enabled, you’re flying blind on payload. You can confirm the request happened but not what was requested or returned. Document that gap now before your CISO asks.

  • Published On Jun 12, 2026 at 12:00 PM IST

Join the community of 2M+ industry professionals.

Subscribe to Newsletter to get latest insights & analysis in your inbox.

All about ETCISO industry right on your smartphone!




Information Security - InfoSec - Cyber Security - Firewall Providers Company in India

 

 

 

 

 

 

 

 

 

 

 

 

What is Firewall? A Firewall is a network security device that monitors and filters incoming and outgoing network traffic based on an organization's previously established security policies. At its most basic, a firewall is essentially the barrier that sits between a private internal network and the public Internet.

 

Secure your network at the gateway against threats such as intrusions, Viruses, Spyware, Worms, Trojans, Adware, Keyloggers, Malicious Mobile Code (MMC), and other dangerous applications for total protection in a convenient, affordable subscription-based service. Modern threats like web-based malware attacks, targeted attacks, application-layer attacks, and more have had a significantly negative effect on the threat landscape. In fact, more than 80% of all new malware and intrusion attempts are exploiting weaknesses in applications, as opposed to weaknesses in networking components and services. Stateful firewalls with simple packet filtering capabilities were efficient blocking unwanted applications as most applications met the port-protocol expectations. Administrators could promptly prevent an unsafe application from being accessed by users by blocking the associated ports and protocols.

 

Firewall Firm is an IT Monteur Firewall Company provides Managed Firewall Support, Firewall providers , Firewall Security Service Provider, Network Security Services, Firewall Solutions India , New Delhi - India's capital territory , Mumbai - Bombay , Kolkata - Calcutta , Chennai - Madras , Bangaluru - Bangalore , Bhubaneswar, Ahmedabad, Hyderabad, Pune, Surat, Jaipur, Firewall Service Providers in India

Sales Number : +91 95 8290 7788 | Support Number : +91 94 8585 7788
Sales Email : sales@itmonteur.net | Support Email : support@itmonteur.net

Register & Request Quote | Submit Support Ticket