Bishop Fox disclosed widespread public data exposure risks in ServiceNow environments caused by misconfigured access controls and portal settings rather than a single platform zero-day. In 166 authorized assessments, the firm found that 31% of instances exposed data to unauthenticated users, with positive findings affecting roughly three-quarters of the organizations represented in those cases. The exposures were observed on Service Portal widgets and the Table REST API, where public sessions could sometimes retrieve full backend records or at least confirm record counts without credentials.
Researchers said the stock ticket-attachments widget was a frequent source of exposure, leaking metadata tied to internal business processes and potentially revealing sensitive operational details. To help defenders identify these weaknesses, Bishop Fox released Snowpick, an open-source Go-based scanner that tests public ServiceNow surfaces from an unauthenticated perspective, distinguishes full-record exposure from count-only leaks, and produces bounded evidence for remediation. The findings reinforce that organizations must validate widget behavior, table access, and ACL enforcement independently on any publicly reachable ServiceNow instance.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
Bishop Fox released Snowpick, an open-source Go tool for testing ServiceNow instances from an unauthenticated perspective for row-level and count-only data exposure. The tool was presented as a way for defenders to identify customer-specific configuration weaknesses rather than a platform zero-day.
Bishop Fox reported that in 166 authorized ServiceNow assessments, 31% of instances had at least one unauthenticated data exposure finding caused by ACL or portal misconfigurations. The exposures were observed via public Service Portal widgets and the Table REST API, with the ticket-attachments widget cited as the most common vector.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
helpnetsecurity.com
Open sourcebishopfox.com
Open sourceenumerated.ie
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.