Worrying ServiceNow security flaw could let hackers steal private table data

Image for article Worrying ServiceNow security flaw could let hackers steal private table data
News Source : TechRadar

News Summary

  • Fault in ServiceNow could have allowed threat actors to exfiltrate sensitive data from other user’s tables
  • The flaw, tracked as CVE-2025-3648 and given a severity score of 8
  • 2/10 (high), was spotted by security researchers Varonis
  • The bug stems from faulty Access Control Lists (ACLs), used to restrict access to data within the tables
A mishap in ServiceNow access control lists meant users could be granted access, without meeting all the conditionsNew controls were added to mitigate the riskUsers are advi [+2163 chars]

Must read Articles