Safely manage your Zendesk from the AI assistant you already use, via the Deltastring MCP. Beacon configuration platform
← Back to news

ServiceNow discloses security incident exposing customer data

ServiceNow disclosed a security incident on 9 June 2026 after attackers exploited an unauthenticated API endpoint to query customer instance data. The vulnerability existed in a REST endpoint at '/api/now/related_list_edit/create' that was configured to accept unauthenticated requests, allowing threat actors to access sensitive information stored across ServiceNow instances without credentials. ServiceNow applied a security patch on 5 June and notified affected customers through support bulletins and direct cases, though the company has not publicly disclosed which specific data was accessed or the full scope of the breach. The vulnerability primarily affected customers running the Australia platform release or those on older releases with certain configuration modifications. Whilst ServiceNow has not confirmed whether customer data was stolen, the company confirmed that attackers successfully queried instance tables—a concerning detail given that ServiceNow instances typically contain IT support tickets, employee records, internal documentation, asset inventories, security incident reports, and system configuration details.

For CX teams relying on ServiceNow for ticketing and knowledge management, this incident raises immediate questions about data exposure in support cases. Support tickets are particularly valuable to threat actors because they frequently contain credentials, API tokens, internal documentation, and authentication secrets shared during troubleshooting—precisely the kind of sensitive information that could compromise downstream systems and customer trust. The quiet disclosure approach, with details hidden behind a customer support portal and only discovered through Reddit discussions, suggests ServiceNow prioritised controlled communication over transparency. This raises a critical question: how should CX leaders assess vendor security disclosure practices when evaluating whether to consolidate customer data across platforms like ServiceNow, Salesforce, or similar enterprise systems?

The incident also exposes a broader architectural risk in enterprise CX infrastructure. An unauthenticated API endpoint existing in production—particularly one handling data access—indicates a gap between development and security practices that should concern any organisation storing customer or employee data in these systems. CX teams should immediately audit their ServiceNow configurations, review access logs for the vulnerable endpoint using the shared indicator (IP 51.159.98.241), and assess what sensitive information exists in their support tickets. Whether ServiceNow publishes a CVE or not, this incident demonstrates that even mature, widely-deployed platforms can harbour fundamental authentication oversights, making vendor security posture a material factor in CX technology decisions.