logo

Thousands of orgs at risk of knowledge base data leaks via ServiceNow misconfigurations

ID: ef035913-bcf6-51db-8556-a6a177d41946

STIX ID: report--ef035913-bcf6-51db-8556-a6a177d41946

Feed Name: The Register (Security)

Threat Score
70/100

Date Published: 2024-09-19

Date Updated: 2026-04-26

Author: Connor Jones

...
...

Security researchers disclosed that ServiceNow Knowledge Base widgets can be misconfigured such that 'private' KB articles are retrievable by unauthenticated actors: the KB Article Page widget permits enumeration of predictable article IDs (KBXXXXXXX) and, with the g_ck JavaScript token, an attacker can POST requests to obtain full article content. Estimates suggest a large portion of ServiceNow instances (roughly 30–45%) were vulnerable; mitigations include applying proper User Criteria, ensuring relevant Business Rules are active, and following ServiceNow's guidance and proactive configuration fixes.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.