ServiceNow disclosed a security incident after attackers exploited an unauthenticated access flaw in the Scripted REST endpoint /api/now/related_list_edit/create to query data from multiple customer instances. The company said it detected anomalous activity tied to IP address 51.159.98.241, with suspicious access occurring on June 2 and 3, and confirmed successful exploitation. The issue appears to stem from a misconfigured resource with requires_authentication=false, causing requests to be processed as the Guest user; access-control enforcement may also have varied by tenant. Affected environments were reported to include customers on the Australia platform release and some older releases with specific configuration changes.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
On June 9, ServiceNow disclosed that exploitation of an unauthorized access flaw had enabled successful queries against instance tables for a subset of customers. The company said the issue affected Australia release customers and some pre-Australia instances with certain configuration changes, and that impacted customers were notified directly.
ServiceNow said the anomalous activity tied to the vulnerable API now appears to have come from bug bounty or customer security research rather than malicious attackers. It also disclosed that two researchers submitted a report on June 7 and said no data was used or retained.
On June 5, ServiceNow applied a security update to hosted customer instances and changed the affected API endpoint so it required authentication. The company also opened support cases with affected customers and advised them to review logs and assess possible exposure.
On June 2 and 3, a suspicious foreign IP address, 51.159.98.241, accessed multiple tenants through the vulnerable /api/now/related_list_edit/create endpoint. ServiceNow later confirmed successful exploitation of an unauthenticated access flaw that allowed querying data from customer instances.
ServiceNow said reports describing a flaw that could allow unauthenticated access to information in certain instances were first submitted on April 22. This predates the June bug bounty submissions and indicates the issue had been externally reported earlier.
ServiceNow had internally documented the vulnerability affecting the /api/now/related_list_edit/create Scripted REST endpoint on April 7. The issue was reportedly tied to a misconfigured resource with requires_authentication set to false and was initially treated as non-urgent.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
13 references tracked. Mallory keeps watching after this page renders.
cpomagazine.com
Open sourcecysecurity.news
Open sourcethecyberexpress.com
Open sourcerhisac.org
Open sourcetrust.servicenow.com
Open sourcedarkreading.com
Open sourcethecybersecguru.com
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.