{"id":1248,"date":"2026-06-10T07:58:20","date_gmt":"2026-06-10T07:58:20","guid":{"rendered":"https:\/\/thedigitalfortress.us\/?p=1248"},"modified":"2026-06-10T07:58:20","modified_gmt":"2026-06-10T07:58:20","slug":"servicenow-flaw-exploited-to-gain-unauthorized-access-to-customer-instances","status":"publish","type":"post","link":"https:\/\/thedigitalfortress.us\/?p=1248","title":{"rendered":"ServiceNow Flaw Exploited to Gain Unauthorized Access to Customer Instances"},"content":{"rendered":"<div>\n<p><span class=\"p-author\"><i class=\"icon-font icon-user\">\ue804<\/i><span class=\"author\">Ravie Lakshmanan<\/span><i class=\"icon-font icon-calendar\">\ue802<\/i><span class=\"author\">Jun 10, 2026<\/span><\/span><span class=\"p-tags\">Cyber Attack \/ Vulnerability<\/span><\/p>\n<\/div>\n<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgdoQ33nXrsmYyHLAdeWHw4nf5zrUhZhVi755NnYVGzkyNPbpR60m4Rt6w8JiKdPuXgn1Md6_nu253LeMjXG7VyEZcBWMaE-ST8lN8P8QqtACeftxFrV3nyIoF8TEHzX6m2sqjiv6KFz4_4eZoddHKWQYVSQgagI4oW_NcdjcnYrWyNPBbq05O7hdE8zZoj\/s1700-e365\/servicenow.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><\/a><\/div>\n<p>ServiceNow has warned about a security incident in which unknown threat actors exploited a flaw to obtain deeper unauthorized access to susceptible instances.<\/p>\n<p>\u00abOn June 5, 2026, ServiceNow applied a security update to hosted customer instances,\u00bb the company revealed in an <a href=\"https:\/\/support.servicenow.com\/kb?id=kb_article_view&amp;sysparm_article=KB3067321\">advisory<\/a> that requires customer access. \u00abThe update concerned a security issue that could allow an unauthenticated user, in certain circumstances, to gain greater access to ServiceNow instances than intended.\u00bb<\/p>\n<p>The security update makes changes to an endpoint configuration to limit this access to authenticated users. The security flaw currently does not have a CVE identifier. Details of the issue <a href=\"https:\/\/www.reddit.com\/r\/servicenow\/comments\/1u0c45c\/comment\/oqpciyl\/\">first emerged<\/a> on Reddit.<\/p>\n<p>ServiceNow said it detected anomalous activity relating to the security issue, and that it observed evidence of successful queries of instance tables against a \u00absubset of customers.\u00bb Impacted customers have been notified, it added.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/vpn-threat-report-m\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhFlTC7RrRZGiFAgASS0noWSL0qsQGFVp8-Hvuw9yp3X3VKRuTcb5SsPX09wJzrdIM6pu1_5lS4EeZp7Sx4iYBpNJkrGnpr08yyaS1HQ5_5TxaCsP6O0OtHNuOkesn6CbNjao1GPulCJk-uljYMSfMZfBYNrngpe669t7jlRn1FqiEnXhsFD1WVkpaYIVgh\/s728-e100\/ai-d.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>\u00abThe security issue pertains to customers who are on the Australia platform release or made certain configuration changes to instances on releases prior to Australia,\u00bb it noted.<\/p>\n<p>A Reddit comment from a user named \u00abd3s7iny\u00bb <a href=\"https:\/\/www.reddit.com\/r\/servicenow\/comments\/1u0c45c\/potential_servicenow_breach\/\">claimed<\/a> that its security team reported the vulnerability to ServiceNow, adding that the software company had been aware of the problem internally since April 7, 2026. For about two months, ServiceNow is said to have classified it as a non-urgent issue, with plans to remediate it in a future update.<\/p>\n<p>The Hacker News has contacted ServiceNow for comment, and we will update the story if we hear back.<\/p>\n<p><i>(This is a developing story. Please check back for more details.)<\/i><\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>\ue804Ravie Lakshmanan\ue802Jun 10, 2026Cyber Attack \/ Vulnerability ServiceNow has warned about a security incident in which unknown threat actors exploited a flaw to obtain deeper unauthorized access to susceptible instances.&hellip;<\/p>\n","protected":false},"author":1,"featured_media":1249,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[130,1295,128,70,580,301,1989,1506],"class_list":["post-1248","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-access","tag-customer","tag-exploited","tag-flaw","tag-gain","tag-instances","tag-servicenow","tag-unauthorized"],"_links":{"self":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/1248","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1248"}],"version-history":[{"count":0,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/1248\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/media\/1249"}],"wp:attachment":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1248"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1248"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1248"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}