Worrying ServiceNow security flaw could let hackers steal private table data

News Source : TechRadar
News Summary
- Fault in ServiceNow could have allowed threat actors to exfiltrate sensitive data from other user’s tables
- The flaw, tracked as CVE-2025-3648 and given a severity score of 8
- 2/10 (high), was spotted by security researchers Varonis
- The bug stems from faulty Access Control Lists (ACLs), used to restrict access to data within the tables
A mishap in ServiceNow access control lists meant users could be granted access, without meeting all the conditionsNew controls were added to mitigate the riskUsers are advi [+2163 chars]