ServiceNow, the cloud platform used by thousands of enterprises to automate internal business processes, has notified customers that a software bug was allowing anyone on the internet to access their data without credentials. The company patched affected customer instances on June 5, 2026.
The bug permitted unauthenticated users to “gain greater access” to ServiceNow-hosted data than intended, meaning no password or login was required to view the exposed information. ServiceNow said the issue relates to customer instances running its Australia releases, though several users on Reddit reported finding evidence of external access on instances running other software versions as well.
ServiceNow told TechCrunch the incident was not the result of malicious hacking, but rather the work of security researchers participating in a bug bounty program. “The security researchers have advised their activity was solely for bug bounty submissions and no data was used or retained,” said company spokesperson Courtney Johnson. ServiceNow did not name the researchers or disclose how many customers were affected.
Network defenders shared an IP address — 51.159.98.241 — as an indicator of potential data access that customers can search for in their logs.
Because the exposure stemmed from a platform-level bug rather than a configuration error, it is unclear whether affected customers could have taken steps to protect themselves before the patch was applied.
The incident highlights the potential risk posed by platforms like ServiceNow, which store sensitive enterprise data including IT and HR system information, customer support tickets, and credentials. Companies use the platform to build automated workflows for tasks such as onboarding staff, resolving tech support tickets, and running chatbots — making it a potentially high-value target given the volume and sensitivity of data it holds.
Source: TechCrunch