logo

Thousands of ServiceNow KB Instances Expose Sensitive Corporate Data

ID: 93600cf0-47bf-5cea-9c6f-dedbe0cf1eec

STIX ID: report--93600cf0-47bf-5cea-9c6f-dedbe0cf1eec

Feed Name: Dark Reading

Threat Score
70/100

Date Published: 2024-09-18

Date Updated: 2026-04-21

Author: Elizabeth Montalbano, Contributing Writer

...
...

AppOmni research found that approximately 45% of enterprise ServiceNow knowledge base instances — roughly one thousand KBs — exposed sensitive data (PII, internal system details, and active credentials) because of misconfigured access controls and insecure default KB properties; ServiceNow coordinated mitigations with customers and recommended administrators run diagnostics, deny unauthenticated access by default, and apply security updates.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.