ServiceNow Flaw Exploited to Gain Unauthorized Access to Customer Instances
ServiceNow has disclosed a security incident where an unknown threat actor exploited a vulnerability to gain unauthorized access to customer instances. The flaw, initially discovered and internally tracked by ServiceNow since April 7, 2026, allowed unauthenticated users to access ServiceNow instances beyond intended limits. The company has since applied a security update to mitigate the risk, notifying affected customers and investigating anomalous activity.
On June 5, 2026, ServiceNow addressed a security vulnerability within its platform that enabled unauthorized access to customer instances. The issue, detailed first on Reddit by a user named ‘d3s7iny,’ allowed an unauthenticated user to gain greater access to ServiceNow instances than intended, specifically impacting customers utilizing the Australia platform release or those with specific configuration changes on older releases. ServiceNow detected anomalous activity and confirmed successful queries of instance tables against a subset of its customer base, prompting immediate action to contain the threat.
