logo

Snowpick: Open-source ServiceNow exposure scanner

ID: cb281a93-05b1-5389-b2bc-6d3d99c11559

STIX ID: report--cb281a93-05b1-5389-b2bc-6d3d99c11559

Feed Name: Help Net Security

Threat Score
70/100

Date Published: 2026-07-22

Date Updated: 2026-07-22

Author: Mirko Zorz

...
...

Bishop Fox released Snowpick and a research write-up showing that misconfigurations in ServiceNow public surfaces (Service Portal widgets and the Table REST API) allowed unauthenticated sessions to retrieve or infer records from many instances — roughly 31% of 166 tested instances returned data or counts, exposing attachments, knowledge-base articles, ticket metadata, and other internal information. The issues are primarily access-control and configuration problems rather than new platform zero-days; the public release aims to accelerate remediation but also makes probing trivial for attackers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.