ServiceNow warned that a vulnerability may have been used to target customer environments, but the company has since attributed this activity to bug bounty research. The business workflow software company yesterday informed customers that, through a gated knowledge base article, the company detected anomalous activity related to a "security issue." The issue, which the company did not explicitly call a vulnerability, could allow greater access than intended. Moreover, an unauthorized user was able to successfully query certain instance tables belonging to a subset of ServiceNow customers. The issue was addressed in a June 5 update, which was applied to hosted customer instances. In the initial knowledge base article, the only technical detail described was that "The security update changes an endpoint configuration to limit access to authenticated users." "The security issue pertains to customers who are on the Australia platform release or made certain configuration changes to instances on releases prior to Australia," the company said. "If you have not received a case from us, then we did not observe such activity in connection with your instance and no action is currently required." Today, ServiceNow published an additional security notice, which is public facing, that clarifies that, based on the company's investigation, it believes "the observed activity is attributable to security researchers or customer research." "On June 3-4, 2026, customers shared submissions to the...
Bug Bounty Research Triggers ServiceNow Security Alert
Dark Reading
·Alexander Culafi
·Published Jun 10, 2026
·Updated
Affected Software
1 affected component
ServiceNow Now Platform=Australia, <Australia
Frequently Asked Questions
1
What incident triggered the security alert from ServiceNow?
The security alert was triggered by bug bounty research that was initially suspected to be a vulnerability targeting customer environments.
2
What is the primary security concern mentioned in the article?
The primary security concern is the detection of an activity that could have been mistaken for an exploitation of a vulnerability in customer environments.
3
How did ServiceNow communicate the findings to its customers?
ServiceNow communicated the findings through a gated knowledge base article to inform customers about the situation.
4
What product is specifically mentioned as being related to the security alert?
The ServiceNow Now Platform is specifically mentioned in relation to the security alert.
5
What is the outcome of the investigation into the security alert?
The outcome of the investigation revealed that the detected activity was part of authorized bug bounty research, not a malicious threat.