Monday, August 3, 2026

Compute & Cloud

ServiceNow patches bug that allowed unauthenticated data access

ServiceNow patched a bug that allowed unauthenticated users to access customer data, though the company states the activity was conducted by security researchers, not bad actors.

ServiceNow patches bug that allowed unauthenticated data access
Photo: ServiceNow

Enterprise software provider ServiceNow has patched a software bug that allowed unauthenticated users to access customer data. ServiceNow operates as a cloud computing platform that allows enterprise customers to automate internal business processes and build workflows connecting various databases. In this context, unauthenticated users refers to individuals accessing a system without providing credentials such as passwords. On June 5, the company patched some customer instances to address the vulnerability. Prior to this patch, a software bug on its platform was allowing anyone on the internet to access their data.

The company clarified that the security incident was not a hack. Instead, ServiceNow stated that the activity was the work of security researchers who were looking for vulnerabilities to submit to a bug bounty program. A bug bounty program is a structured initiative where companies pay security researchers to find and report vulnerabilities. ServiceNow spokesperson Courtney Johnson confirmed that the company investigated the activity and established contact with the researchers who initially reported the issue. Johnson noted that evidence of the observed activity came from those security researchers and customer research teams, rather than malicious bad actors. According to Johnson, “The security researchers have advised their activity was solely for bug bounty submissions and no data was used or retained.”

Regarding the scope of the vulnerability, ServiceNow stated that the issue relates to customer instances running Australia releases, which refers to a specific software versioning nomenclature rather than a geographic location. However, network defenders and security teams monitoring their environments have identified the IP address 51.159.98.241 as an indicator of potential data access. If this IP address is found within a customer’s system logs, it may indicate that their specific instance was accessed during the period the vulnerability was active.

Why it matters

ServiceNow manages critical enterprise workflows and sensitive data, making it a high-value target for potential exploitation if security vulnerabilities are left unpatched.