Threat Advisory: ServiceNow unauthenticated data access vulnerability
A recent security incident involving ServiceNow highlights a significant risk to enterprises relying on cloud workflow and IT service management platforms. ServiceNow disclosed that a software flaw affecting certain customer instances allowed unauthenticated access to data via a vulnerable API endpoint. This condition effectively bypassed authentication controls, enabling external parties to query stored data without valid credentials.