Reporting describes an unauthenticated API endpoint flaw affecting ServiceNow, permitting table query access, with an activity window in early June 2026 and impact described as varying by customer instance.
That last clause carries most of the weight. In multi-tenant enterprise software, the severity of a platform defect is not one number — it is a distribution across every tenant, determined by choices each of them made independently.
Same Defect, Different Consequences
What a table query reaches depends on what a given organisation put in its tables. ServiceNow instances hold IT service records for some customers and HR cases, security incidents, vendor contracts or customer data for others. The platform is identical; the exposure is not.
The consequence is that customers cannot assess a platform advisory from the advisory alone. The vendor can describe the mechanism and the affected versions, but only the customer knows what was reachable, and answering that means an inventory most organisations do not maintain.
Unauthenticated Is The Word To Notice
Most access-control failures require an attacker to hold something first — a credential, a session, a foothold. An unauthenticated flaw requires only reachability, which collapses the population of potential attackers to everyone who can route to the endpoint.
It also removes the detection surface most organisations rely on. There is no anomalous sign-in, no unusual account behaviour, no impossible-travel alert. There is a request, and it is served.
Compiled from public reporting, listed below. Per-tenant impact has not been disclosed and we are not estimating it. Corrections: corrections@forensicpost.com.
- List of recent data breaches in 2026Bright Defense