Cloud computing giant ServiceNow has warned its enterprise clients that a critical software vulnerability on its platform recently allowed unauthenticated internet users to access private corporate data.
Unauthorised Access to Cloud Databases
According to a knowledge base article, which the company restricted behind a login wall but was subsequently leaked on Reddit, ServiceNow deployed patches on 5 June to resolve a flaw that granted unauthorised users “greater access” to hosted databases than intended.
This security flaw essentially enabled anyone on the web to bypass standard credential checks, such as passwords, to view sensitive information stored within customer instances.
White-Hat Researchers, Not Malicious Hackers
In a statement to TechCrunch, ServiceNow clarified that the exposure was uncovered by security researchers hunting for vulnerabilities as part of a bug bounty initiative, rather than malicious cybercriminals.
“Alongside our own investigation, we have been in contact with the security researchers who initially reported this issue and can confirm that evidence of the observed activity came from those security researchers and customer research teams, not bad actors,” stated ServiceNow spokesperson Courtney Johnson. She added that the researchers confirmed their activities were strictly for bug bounty submissions and that no harvested data was retained or utilised.
However, ServiceNow declined to name the researchers involved or disclose the exact number of corporate customers whose data had been accessed during the probes.
Because the incident originated from a platform-level software bug, it remains uncertain whether affected enterprises could have implemented any preventative measures to protect their data prior to the official patch rollout.
The High-Value Target of Enterprise Workflows
As a dominant force in cloud computing, ServiceNow helps thousands of global organisations automate vital internal operations. Enterprises rely on the platform to construct complex workflows linking databases with IT and HR systems. These systems manage highly sensitive everyday tasks, including staff onboarding, resolving IT support tickets, and operating automated chatbots.
This deep integration makes platforms like ServiceNow incredibly lucrative targets for cyber threats. The databases they host often contain highly sensitive credentials, passwords, cryptographic keys, and internal support logs.
Affected Software Versions and Indicators of Compromise
While ServiceNow stated that the vulnerability specifically impacts customer instances running its Australia releases (a software version name unrelated to geography), multiple users on Reddit claim to have detected external access attempts on systems running entirely different software versions.
To assist organisations in checking their systems, cybersecurity defenders have flagged a specific IP address, 51.159.98.241, which may indicate unauthorised data access if found within a company’s network logs.
