Threat reportVulnerabilityTL-2026-0980
ServiceNow Scripted REST Resource Unauthenticated Access - /api/now/related_list_edit/create
ServiceNow Scripted REST Resource Unauthenticated Access (TL-2026-0980), also tracked as ServiceNow related_list_edit Unauthenticated Access, is a critical-severity software vulnerability, first published 2026-06-09. It has no confirmed attribution, affects ServiceNow Now Platform, maps to 15 MITRE ATT&CK techniques (T1016, T1030, T1048), and is covered by 9 detection rules and 15 indicators of compromise.
- Severity
- CRITICALAssessed severity
- CVEs
- 0None referenced
- Techniques
- 15MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 15Indicators of compromise
Key facts for TL-2026-0980
- Threat ID
- TL-2026-0980
- Also known as
- ServiceNow related_list_edit Unauthenticated Access, ServiceNow API Authentication Bypass
- Severity
- CRITICAL
- Status
- ACTIVE
- Category
- VULNERABILITY
- First published
- Last reviewed
- Attribution confidence
- NONE
- Motivation
- UNKNOWN
- Target sectors
- software-development, cloud-infrastructure, financial-services, health, government administration, manufacturing, telecoms
- Target regions
- EMEA, AMER, APAC
- Detection rules
- 9
- Indicators of compromise
- 15
How ServiceNow Scripted REST Resource Unauthenticated Access works
A Scripted REST Resource endpoint (/api/now/related_list_edit/create) on ServiceNow systems was configured with unauthenticated access (requires_authentication = false). Attackers from IP 51.159.98.241 successfully accessed backend functionality and executed table queries without authentication.
A critical misconfiguration in ServiceNow Scripted REST Resources allowed unauthenticated access to the /api/now/related_list_edit/create endpoint. The endpoint was configured with requires_authentication set to false, bypassing standard authentication and authorization controls. Security researchers and affected customers observed multiple successful access attempts originating from IP address 51.159.98.241 (OVH SA infrastructure, France). The attacker was able to execute backend queries and access related list data without providing valid credentials. Affected systems included customer instances running the Australia release and those with certain pre-release configuration changes. Because requests were processed without an authenticated user context, activity was logged under the Guest user account, complicating forensic analysis and attribution. ServiceNow indicated that successful table queries were observed in a subset of customer environments, suggesting potential data exfiltration. The vulnerability appears to stem from improper configuration of Scripted REST API endpoints rather than a traditional code vulnerability, though it represents a serious authentication bypass. Multiple customers were notified directly by ServiceNow regarding the scope of exposure.
MITRE ATT&CK techniques used in TL-2026-0980
Discovery
T1016 System Network Configuration Discovery; T1526 Cloud Service Discovery
Exfiltration
T1030 Data Transfer Size Limits; T1048 Exfiltration Over Alternative Protocol
Command and Control
T1071 Application Layer Protocol
Collection
T1074 Data Staged; T1213 Data from Information Repositories
Initial Access
T1133 External Remote Services; T1190 Exploit Public-Facing Application
Impact
T1485 Data Destruction; T1486 Data Encrypted for Impact
Privilege Escalation
T1548 Abuse Elevation Control Mechanism
Lateral Movement
T1550 Use Alternate Authentication Material
defense-impairment
T1556 Modify Authentication Process
defense-evasion
Affected products and versions in ServiceNow Scripted REST Resource Unauthenticated Access
- ServiceNow — Now Platform
Vulnerable versions: Australia release; Pre-release versions with configuration changes
Remediation for ServiceNow Scripted REST Resource Unauthenticated Access
Patches
- Apply ServiceNow security patches for authentication validation
- Update Scripted REST Resource configurations to enforce requires_authentication = true
- Implement API access controls via ACLs on related_list_edit and similar endpoints
Immediate actions
- Audit all Scripted REST Resource endpoints for requires_authentication = false configuration
- Review API access logs for requests from IP 51.159.98.241 and similar external IPs
- Check Guest user account activity logs for suspicious table queries
- Block IP 51.159.98.241 and OVH IP ranges 51.159.0.0/16 at perimeter if not required
- Enable request logging and monitoring on all REST API endpoints
Workarounds
- Disable the /api/now/related_list_edit/create endpoint if not required
- Restrict endpoint access via network firewall rules to known internal sources only
- Implement reverse proxy authentication layer in front of ServiceNow
Longer-term hardening
- Implement API gateway with authentication enforcement before ServiceNow instance
- Deploy EDR with behavioral detection for suspicious database queries
- Enforce API authentication requirements via policy in development/configuration controls
- Implement network segmentation to restrict API access to known sources
- Deploy UEBA to detect anomalous guest account activity
- Implement query activity monitoring on backend tables
- Review and audit all Scripted REST Resources and custom API endpoints
Weaknesses (CWE) in ServiceNow Scripted REST Resource Unauthenticated Access
Timeline of ServiceNow Scripted REST Resource Unauthenticated Access
- ServiceNow confirms observing successful table queries in subset of customer environments; notifies affected customers directly
- Multiple instances of successful access attempts from IP 51.159.98.241 confirmed by security researchers and affected customers
- Security researchers publicly disclose /api/now/related_list_edit/create endpoint misconfiguration allowing unauthenticated access
- Wiz Threat Intelligence publishes detailed analysis of ServiceNow unauthenticated access incident affecting Australia release and pre-release environments
- Security researchers on Twitter/X begin analyzing incident scope and implications for ServiceNow customer base
- Reddit r/servicenow community discusses incident; multiple customers report similar unauthenticated access attempts in their logs
- Forensic analysis reveals requests logged under Guest user account, complicating attribution and forensic timeline reconstruction
- ServiceNow provides guidance to customers on auditing Scripted REST Resource configurations and enforcing requires_authentication parameter
Sources cited for ServiceNow Scripted REST Resource Unauthenticated Access
Detection coverage for TL-2026-0980
As of 2026-06-09, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0980 across Splunk SPL, Microsoft KQL and Sigma, covering 15 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.