Developing event. Generated by AI and subject to further corroboration and review.
ServiceNow discloses API vulnerability exposing customer instance data
ServiceNow disclosed that attackers exploited an unauthenticated API endpoint on its enterprise SaaS platform to query customer instance data. The vendor applied a security update to hosted instances on June 5, 2026, and is notifying affected customers via support cases. Exposure is concentrated on the Australia platform release and older releases with specific configuration changes. Reporting from BleepingComputer, TechCrunch, and TechRadar corroborates the disclosure, while vendor opacity on affected customer count, access duration, and exfiltration scope continues to constrain downstream severity banding.
AI-generated from linked source reports. See our correction policy.
Impact verdict
Medium impact. MEDIUM: ServiceNow is a widely deployed enterprise SaaS platform used by large corporates likely insured across London cyber, tech E&O, and casualty books, creating aggregated supply-chain exposure on first-party and third-party liability covers. Public reporting indicates queried instance data may include IT support tickets, internal documentation, employee records, asset inventories, security incident reports, and potentially credentials or API tokens, elevating downstream incident-response and notification burden. Materiality is tempered by the absence of confirmed mass exfiltration, ransomware activity, or critical-infrastructure impact, and by vendor containment via the June 5 hosted-instance update. Vendor opacity on scope per TechRadar constrains severity banding absent insurer-side notification data.
View assessment methodologyHow we grade what we know -- Known · Reported · Uncertain. Methodology →
Intelligence ledger
Each line expands in place to its underlying sourced claim.
Known52 lines
ServiceNow applied a security update to hosted customer instances on June 5, 2026▾
Attackers exploited an unauthenticated access flaw through a vulnerable API endpoint (/api/now/related_list_edit/create)▾
The API endpoint was allegedly configured with requires_authentication=false▾
Attackers successfully queried customer instance tables▾
ServiceNow has opened support cases with affected customers▾
Vulnerability primarily impacts customers on Australia platform release or older releases with specific configuration changes▾
No public reporting indicates ransomware activity, mass exfiltration confirmation, or critical-infrastructure impact associated with the incident to date.▾
Disclosure and customer notification are corroborated by BleepingComputer, TechCrunch, and TechRadar reporting.▾
Public reporting has not confirmed mass exfiltration, ransomware activity, or critical-infrastructure impact in connection with the ServiceNow incident.▾
Vulnerability impact is primarily concentrated on customers using the Australia platform release and on older ServiceNow releases with specific configuration changes; the broader installed base exposure is not quantified in public reporting.▾
Exposure is primarily concentrated on customers on the ServiceNow Australia platform release and on older releases with specific configuration changes.▾
Public reporting does not confirm ransomware activity, mass data exfiltration, or critical-infrastructure impact associated with the disclosed flaw.▾
Vulnerability primarily impacts customers on the Australia platform release or on older releases with specific configuration changes.▾
ServiceNow is a US-headquartered enterprise SaaS provider with globally distributed hosted instances; affected instances are concentrated on the Australia platform release region.▾
Impact is concentrated on customers on the Australia platform release or on older releases with specific configuration changes.▾
The vulnerability primarily impacts customers on the Australia platform release or older releases with specific configuration changes.▾
The exploited endpoint is identified as /api/now/related_list_edit/create, allegedly configured with requires_authentication=false.▾
Vulnerability primarily impacts customers on the Australia platform release and on older releases with specific configuration changes.▾
ServiceNow disclosed that attackers exploited an unauthenticated access flaw through a vulnerable API endpoint, allowing them to query data from customer instances.▾
The exploited API endpoint is /api/now/related_list_edit/create, which was allegedly configured with requires_authentication=false.▾
Exposure is concentrated on customers on the Australia platform release and on older releases with specific configuration changes.▾
Attackers exploited an unauthenticated access flaw via a vulnerable ServiceNow API endpoint (reported as /api/now/related_list_edit/create) that was configured with requires_authentication=false, allowing query access to customer instance tables.▾
Attackers exploited an unauthenticated API endpoint vulnerability, configured with requires_authentication=false, to query customer instance tables.▾
ServiceNow disclosed a security incident in which attackers exploited an unauthenticated API endpoint vulnerability to query data from customer instances on its enterprise SaaS platform.▾
Attackers exploited the unauthenticated API endpoint /api/now/related_list_edit/create, which was reportedly configured with requires_authentication=false, to query customer instance tables.▾
Exposure is concentrated on customers running the Australia platform release and on older releases with specific configuration changes.▾
Attackers successfully queried customer instance tables via the vulnerable endpoint, confirming unauthorized data access (not merely theoretical exposure).▾
ServiceNow disclosed a security incident in which attackers exploited an unauthenticated API endpoint vulnerability to query data from customer instances.▾
Vulnerability primarily impacts customers on the Australia platform release or on older releases with specific configuration changes.▾
Attackers successfully queried customer instance tables following exploitation of the unauthenticated API endpoint.▾
The event is classified as a supply-chain SaaS incident with potential aggregated exposure across London cyber and tech E&O portfolios.▾
Event lifecycle is developing, with corroboration threshold met and ongoing source monitoring.▾
ServiceNow applied a security update to hosted customer instances on June 5, 2026, and has opened support cases with affected customers.▾
ServiceNow has opened support cases with affected customers and has stated that all impacted organizations have been notified.▾
ServiceNow applied a security update to hosted customer instances on June 5, 2026.▾
ServiceNow has opened support cases with affected customers.▾
Event tracked as a signal-stage supply-chain SaaS incident pending confirmed scope and loss data.▾
ServiceNow has opened support cases with affected customers to notify them of the security incident and required remediation actions.▾
ServiceNow applied a security update to hosted customer instances on June 5, 2026, addressing the unauthenticated API endpoint vulnerability.▾
ServiceNow applied a security update to hosted customer instances on June 5, 2026 to remediate the unauthenticated API endpoint vulnerability.▾
The event remains in signal lifecycle status pending confirmation of scale and exfiltration scope.▾
ServiceNow has opened support cases with affected customers to coordinate response and notification.▾
ServiceNow has opened support cases with affected customers as part of its incident response.▾
ServiceNow deployed a security update to hosted customer instances on June 5, 2026, to remediate the vulnerability.▾
ServiceNow applied a security update to hosted customer instances on June 5, 2026, as the containment action for the disclosed flaw.▾
ServiceNow has opened support cases with affected customers to communicate exposure and remediation steps.▾
ServiceNow deployed a security update to hosted customer instances on June 5, 2026.▾
ServiceNow has opened support cases with affected customers as part of its notification process.▾
ServiceNow publicly disclosed a security incident in which an unauthenticated API endpoint flaw was exploited to query data from hosted customer instances; a security update was applied to hosted instances on June 5, 2026, and support cases were opened with affected customers.▾
ServiceNow applied a security update to hosted customer instances on June 5, 2026 to remediate the vulnerability.▾
ServiceNow has opened support cases with affected customers to notify them of the incident.▾
ServiceNow disclosed a security incident involving an unauthenticated API endpoint flaw that could allow unintended access to customer instances.▾
Reported35 lines
Instance data may include IT support tickets, employee records, internal documentation, asset inventories, security incident reports, and configuration details▾
Indicators of compromise include API requests from IP address 51.159.98.241▾
Support cases and tickets may contain credentials, API tokens, and authentication secrets▾
TechRadar reports that ServiceNow has revealed a security issue but will not disclose details on what specifically happened, constraining downstream insured-impact assessment.▾
ServiceNow has declined to disclose specifics on the nature or scope of the incident, limiting downstream insured-impact assessment.▾
Public reporting indicates queried instance data may include IT support tickets, internal documentation, employee records, asset inventories, security incident reports, and configuration details; support cases and tickets may further contain credentials, API tokens, and authentication secrets.▾
The vendor has disclosed the existence of the bug and notified customers, but has not publicly disclosed specifics on the nature, scope, or root cause of the incident, limiting insurer-side assessment of insured impact.▾
Reporting indicates queried instance data may include IT support tickets, internal documentation, employee records, asset inventories, security incident reports, configuration details, and potentially credentials or API tokens.▾
Public reporting does not confirm mass data exfiltration, ransomware activity, or critical-infrastructure impact associated with the incident.▾
Instance data potentially exposed may include IT support tickets, employee records, internal documentation, asset inventories, security incident reports, and configuration details.▾
Support cases and tickets may contain credentials, API tokens, and authentication secrets, increasing downstream secret-rotation and credential-reuse risk.▾
ServiceNow is a US-headquartered enterprise SaaS provider; affected instances are globally distributed, with specific exposure on the Australia platform release region.▾
Instance data potentially exposed may include IT support tickets, employee records, internal documentation, asset inventories, security incident reports, and configuration details. Reporting further indicates support cases and tickets may contain credentials, API tokens, and authentication secrets.▾
Potentially exposed instance data may include IT support tickets, employee records, internal documentation, asset inventories, security incident reports, and configuration details. Support cases and tickets may contain credentials, API tokens, and authentication secrets.▾
Instance data that may have been queried includes IT support tickets, internal documentation, employee records, asset inventories, security incident reports, and configuration details. Support cases and tickets may contain credentials, API tokens, and authentication secrets.▾
Indicators of compromise include API requests from IP address 51.159.98.241.▾
Queried instance data may include IT support tickets, internal documentation, employee records, asset inventories, security incident reports, configuration details, and potentially credentials, API tokens, and authentication secrets.▾
Indicators of compromise include API requests originating from IP address 51.159.98.241.▾
A published indicator of compromise includes API requests originating from IP address 51.159.98.241.▾
Public reporting indicates queried instance data may include IT support tickets, employee records, internal documentation, asset inventories, security incident reports, and configuration details, and that support cases and tickets may contain credentials, API tokens, and authentication secrets.▾
Public reporting identifies IP address 51.159.98.241 as a published indicator of compromise associated with API requests exploiting the vulnerability.▾
The exploited unauthenticated API endpoint was reported as /api/now/related_list_edit/create, allegedly configured with requires_authentication=false.▾
Indicators of compromise include API requests originating from IP address 51.159.98.241.▾
Attackers exploited an unauthenticated access flaw through the /api/now/related_list_edit/create endpoint, which was allegedly configured with requires_authentication=false.▾
Indicators of compromise include API requests originating from IP address 51.159.98.241.▾
Attackers reportedly exploited the API endpoint /api/now/related_list_edit/create, which was configured with requires_authentication=false, to query customer instance tables.▾
Reporting cites IP address 51.159.98.241 as an indicator of compromise associated with API requests against the vulnerable endpoint.▾
An indicator of compromise has been reported as API requests originating from IP address 51.159.98.241.▾
If employee records or personal data were accessed across multiple insured entities, casualty lines with cyber-triggered liability components may face secondary notification and regulatory exposure.▾
The ServiceNow incident creates a potential technology errors and omissions exposure pathway for the vendor itself and, depending on contract terms, for downstream corporate users of the platform.▾
Given ServiceNow's broad enterprise SaaS footprint, multiple insured entities may be concurrently affected, creating aggregated supply-chain exposure across London cyber, tech E&O, and casualty lines.▾
The event is a supply-chain SaaS incident with potential aggregated exposure across London cyber and tech E&O portfolios for insureds using ServiceNow.▾
ServiceNow is a widely deployed enterprise SaaS platform used by large corporates likely insured across London cyber, tech E&O, and casualty books, creating potential aggregated supply-chain exposure on both first-party and third-party liability covers.▾
Public reporting notes the event potentially implicates tech E&O and third-party liability coverage for downstream corporate users of the platform.▾
ServiceNow's wide enterprise deployment creates aggregated supply-chain exposure across London cyber, tech E&O, and casualty books, with potential first-party incident response and third-party liability notification activity for insureds running ServiceNow.▾
Uncertain18 lines
Exact number of affected customers and instances▾
Duration of attacker access and extent of data exfiltration▾
Whether a CVE will be published for the vulnerability▾
Specific data categories that were accessed across affected instances▾
Whether a CVE will be published for the vulnerability is unconfirmed in public reporting.▾
The duration of attacker access and the extent of data exfiltration have not been publicly confirmed.▾
The exact number of affected customers and instances has not been publicly confirmed.▾
The duration of attacker access and the extent of data exfiltration are unconfirmed in public reporting.▾
The exact number of affected customers and instances is unconfirmed in public reporting.▾
Whether a CVE will be published for the vulnerability is unconfirmed.▾
The specific data categories that were actually accessed across affected instances are unconfirmed in public reporting.▾
The exact number of affected customers and instances, the duration of attacker access, the extent of data exfiltration, whether a CVE will be published, and the specific data categories accessed across affected instances remain unconfirmed.▾
The exact number of affected customers and instances, the duration of attacker access, the extent of data exfiltration, and whether a CVE will be published remain unconfirmed.▾
ServiceNow has not publicly disclosed the number of affected customers or instances; vendor has declined to detail scope, per TechRadar reporting.▾
Duration of attacker access and extent of data exfiltration have not been publicly disclosed by ServiceNow.▾
The exact number of affected customers and instances remains unconfirmed in public reporting.▾
The duration of attacker access and the extent of data exfiltration remain unconfirmed in public reporting.▾
It is not publicly confirmed whether a CVE will be published for the unauthenticated API endpoint vulnerability.▾
Geographic Zone Matches
3 active matches
- TRIA Certified AreasRule-basedConfidence 100%
- Pacific Ring of FireRule-basedConfidence 100%
- Caribbean Hurricane ZoneRule-basedConfidence 100%
Geographic zone matches are RiskEvents spatial/analytical indicators, not coverage determinations or Lloyd's official classifications.
Affected countries
Latest developments
- Confirmed: ServiceNow disclosed exploitation of an unauthenticated API endpoint affecting customer instances. — BleepingComputer
- The vulnerable API endpoint has been publicly identified with associated misconfiguration. — BleepingComputer
- ServiceNow applied a security update to hosted instances on June 5, 2026, and is engaging affected customers via support cases. — BleepingComputer
- Exposure is concentrated on the Australia platform release and older releases with specific configuration changes. — BleepingComputer
- ServiceNow is notifying affected customers via support cases; reporting indicates all impacted organizations have been contacted. — techcrunch.com
- An IP address has been cited as an indicator of compromise associated with the exploitation activity. — BleepingComputer
- Potentially exposed data categories include support tickets, employee records, configuration data, and possibly credentials or API tokens. — BleepingComputer
- ServiceNow has not publicly disclosed the number of affected customers or instances. — techradar.com
Timeline
A zero-authentication API vulnerability in ServiceNow was exploited in a data breach, with the advisory reportedly gated and customers left unaware. ServiceNow is a widely used enterprise SaaS platform, making this a significant supply chain / enterprise application security incident with potential downstream impact on thousands of corporate customers globally.
Source: techtimes.com (Mainstream Media) · View source
ServiceNow has disclosed a security incident where attackers exploited an unauthenticated API endpoint to query data from customer instances. The incident affects ServiceNow's enterprise customer base globally, with potential data exposure across multiple organizations. This represents a supply chain-style data breach impacting a major enterprise SaaS platform used by many large corporations.
Source: r/SecOpsDaily (Social / Community) · View source
Status changed to developing
evidence_trigger: corroboration >= 2
signal -> developing
ServiceNow has disclosed a security incident involving unauthorized access to some customer instances, with limited detail on what data was exposed. The company states all impacted organizations have been notified. This represents a potential data breach and supply chain exposure for ServiceNow's enterprise customer base.
Source: r/cybersecurity (Social / Community) · View source
ServiceNow has revealed a security issue affecting customer data but has not disclosed specifics about the nature or scope of the incident. The lack of transparency limits assessment of potential insured impact across Cyber and Casualty lines, though the company's enterprise SaaS footprint creates potential downstream exposure for many insureds.
Source: techradar.com (Mainstream Media) · View source
ServiceNow disclosed a bug that left some customer data exposed to the internet, prompting notifications to affected customers. The incident relates to a widely used enterprise cloud platform, potentially implicating cyber liability and data breach coverage for downstream corporate users.
Source: techcrunch.com (Mainstream Media) · View source
Initial Detection
ServiceNow disclosed a security incident where attackers exploited an unauthenticated API endpoint flaw to query data from customer instances. The vulnerability primarily affected customers on the Australia platform release or those with specific configuration changes. This is a significant supply-chain/enterprise SaaS breach with potential aggregated exposure across multiple London market cyber and casualty books.
The update concerned a security issue that could allow an unauthenticated user, in certain circumstances, to gain greater access to ServiceNow instances than intended.
Source: BleepingComputer (Trade Media) · View source
Lloyd's classifications
Tracking this kind of risk? Get an email when Cyber events escalate.
Get alerts