ServiceNow has recently disclosed a security issue that exposed customer data due to a flaw in an API endpoint. This vulnerability allowed unauthenticated attackers to query certain customer instance tables, primarily affecting customers using the Australia release or older versions with specific configurations.
Impact on Australian Customers
The security flaw was particularly concerning for customers operating on the Australia platform release. According to ServiceNow, attackers exploited this vulnerability to access customer instance tables, which could potentially contain sensitive enterprise information such as IT support tickets, employee records, and security incident reports. However, the company has not confirmed the exact nature of the data accessed.
Response and Mitigation
ServiceNow applied a fix on June 5, 2026, which reconfigured the API endpoint to restrict access to authenticated users only. The company has notified affected customers by opening support cases, advising them to review logs for requests to /api/now/related_list_edit, especially from the IP address 51.159.98.241. Administrators are also encouraged to update passwords and tokens shared through support workflows and ensure API logging is enabled.
Recommendations for Administrators
ServiceNow has urged administrators to take proactive measures in response to this incident:
- Review logs for suspicious requests, particularly from the specified IP address.
- Examine exposed tickets and records for sensitive information.
- Update any shared passwords and tokens.
- Ensure API logging is active to monitor future access attempts.
Broader Implications
This incident highlights the critical importance of robust API security, especially for platforms handling sensitive enterprise data. For CTOs and technology leaders, it underscores the need for regular security audits and updates to prevent unauthorized access. As digital transformation continues to evolve, ensuring the security of digital platforms remains a top priority.
ServiceNow's swift response and communication with affected customers demonstrate a commitment to addressing security vulnerabilities promptly. However, the lack of detailed information about the breach may leave some customers seeking further clarity on the potential impact.
Overall, this incident serves as a reminder for enterprises to continuously evaluate their cybersecurity measures and ensure that all software components, especially those involving API access, are secure and up-to-date.