ServiceNow has alerted some enterprise customers that a software bug may have exposed their platform data to anyone on the internet, after unauthenticated users were able to access more hosted data than intended.
TL;DR
- ServiceNow patched affected customer instances on June 5 after a bug allowed unauthenticated access to hosted data.
- The company said the activity was linked to security researchers and customer research teams, not malicious hackers.
- The issue was tied to Australia releases, though Reddit users claimed evidence of external access on other versions.
ServiceNow Data Exposure Bug Raises Enterprise Security Concerns
ServiceNow has told some of its enterprise customers that a bug in its cloud platform left certain customer data exposed to the internet.
According to a knowledge base article shared on Reddit after being placed behind a login wall, ServiceNow patched some customer instances on June 5 to fix a flaw that allowed unauthenticated users to “gain greater access” to ServiceNow-hosted data than intended.
In simpler terms, the issue could have allowed anyone on the internet to access data stored in customer instances without needing credentials such as a password.
ServiceNow Says Security Researchers, Not Hackers, Triggered The Activity
ServiceNow told TechCrunch that the incident was not a hack. Instead, the company said the activity came from security researchers looking for vulnerabilities that could be submitted through a bug bounty program.
“Alongside our own investigation, we have been in contact with the security researchers who initially reported this issue and can confirm that evidence of the observed activity came from those security researchers and customer research teams, not bad actors,” said ServiceNow spokesperson Courtney Johnson. “The security researchers have advised their activity was solely for bug bounty submissions and no data was used or retained.”
However, ServiceNow did not immediately identify the researchers or say how many customers had their data accessed when asked by TechCrunch.
Why The ServiceNow Bug Matters For Enterprise Customers
ServiceNow is widely used by enterprises to automate internal business processes and connect workflows across IT, HR, support systems, apps, databases, and chatbots.
That makes the company’s platform highly sensitive. Customer support tickets and internal workflow records can sometimes include passwords, keys, credentials, employee details, and other business-critical information.
Since the issue appears to have stemmed from a data-exposing bug, it remains unclear whether customers could have done anything to prevent improper access before ServiceNow patched the flaw.
Topics For More Insights
- Microsoft Pulls Open-Source GitHub Repos After Malware Targets AI Developers’ Passwords
- Chinese Spy Recruiters Are Turning LinkedIn Job Offers Into An Intelligence Trap
- India’s Wearable Health Tech Firm Ultrahuman Faces Breach Affecting At Least 700 Users
- Iran-Linked Hackers Blamed For LA Metro Breach That Hit Systems And Recovery
Reddit Users Point To Possible Access Beyond Australia Releases
ServiceNow said the issue relates to customer instances running its Australia releases. However, several people on Reddit claimed they found signs of external access to ServiceNow instances running other versions of the company’s software.
Network defenders also shared the IP address 51.159.98.241 as a possible indicator of data access if it appears in customer logs.
For affected customers, the immediate focus will likely be log review, credential checks, and confirmation of whether any sensitive records were accessed. For ServiceNow, the incident raises a familiar cloud security question: when a platform bug exposes enterprise data, how quickly can customers understand what was touched and what remained protected?


