Unauthorized Data Exposure via Range Queries in ServiceNow ACLs
ID: aab14207-f5cc-5272-9e4a-f0038cdeffdb
STIX ID: report--aab14207-f5cc-5272-9e4a-f0038cdeffdb
Feed Name: Kudelski Security
A ServiceNow platform vulnerability was identified that could allow data inference via range queries when access control lists (ACLs) are misconfigured or overly permissive. ServiceNow rolled out a May 2025 security update introducing Deny-Unless query_range ACLs, new ACL frameworks in recent releases, auto-generated ACLs, and auditing tooling; administrators are urged to validate sys_security_attribute and sys_security_acl entries, review use of the public role, and remediate custom fields or exceptions.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
