Desk live·
ForensicPost
Cloud/API/File 26-0609

ServiceNow API Flaw Allowed Unauthenticated Table Queries, Researchers Report

A reported flaw in a ServiceNow API endpoint allowed table queries without authentication. In multi-tenant software, a single missing check is not one organisation’s incident.

Constructed geometry · not a chart of case data
TargetServiceNow
ActorUnattributed
D. Kennedy8 min readConfidence: medium1 source reviewed

Reporting describes an unauthenticated API endpoint flaw affecting ServiceNow, permitting table query access, with an activity window in early June 2026 and impact described as varying by customer instance.

That last clause carries most of the weight. In multi-tenant enterprise software, the severity of a platform defect is not one number — it is a distribution across every tenant, determined by choices each of them made independently.

Same Defect, Different Consequences

What a table query reaches depends on what a given organisation put in its tables. ServiceNow instances hold IT service records for some customers and HR cases, security incidents, vendor contracts or customer data for others. The platform is identical; the exposure is not.

The consequence is that customers cannot assess a platform advisory from the advisory alone. The vendor can describe the mechanism and the affected versions, but only the customer knows what was reachable, and answering that means an inventory most organisations do not maintain.

Unauthenticated Is The Word To Notice

Most access-control failures require an attacker to hold something first — a credential, a session, a foothold. An unauthenticated flaw requires only reachability, which collapses the population of potential attackers to everyone who can route to the endpoint.

It also removes the detection surface most organisations rely on. There is no anomalous sign-in, no unusual account behaviour, no impossible-travel alert. There is a request, and it is served.

How we reported this

Compiled from public reporting, listed below. Per-tenant impact has not been disclosed and we are not estimating it. Corrections: corrections@forensicpost.com.

Sources
  1. List of recent data breaches in 2026Bright Defense
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary