logo

Unauthorized Data Exposure via Range Queries in ServiceNow ACLs

ID: aab14207-f5cc-5272-9e4a-f0038cdeffdb

STIX ID: report--aab14207-f5cc-5272-9e4a-f0038cdeffdb

Feed Name: Kudelski Security

Threat Score
60/100

Date Published: 2025-07-10

Date Updated: 2026-07-22

...
...

A ServiceNow platform vulnerability was identified that could allow data inference via range queries when access control lists (ACLs) are misconfigured or overly permissive. ServiceNow rolled out a May 2025 security update introducing Deny-Unless query_range ACLs, new ACL frameworks in recent releases, auto-generated ACLs, and auditing tooling; administrators are urged to validate sys_security_attribute and sys_security_acl entries, review use of the public role, and remediate custom fields or exceptions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.