Threat reportVulnerabilityTL-2026-0980

ServiceNow Scripted REST Resource Unauthenticated Access - /api/now/related_list_edit/create

criticalACTIVE

ServiceNow Scripted REST Resource Unauthenticated Access (TL-2026-0980), also tracked as ServiceNow related_list_edit Unauthenticated Access, is a critical-severity software vulnerability, first published 2026-06-09. It has no confirmed attribution, affects ServiceNow Now Platform, maps to 15 MITRE ATT&CK techniques (T1016, T1030, T1048), and is covered by 9 detection rules and 15 indicators of compromise.

Severity
CRITICALAssessed severity
CVEs
0None referenced
Techniques
15MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
15Indicators of compromise

Key facts for TL-2026-0980

Threat ID
TL-2026-0980
Also known as
ServiceNow related_list_edit Unauthenticated Access, ServiceNow API Authentication Bypass
Severity
CRITICAL
Status
ACTIVE
Category
VULNERABILITY
First published
Last reviewed
Attribution confidence
NONE
Motivation
UNKNOWN
Target sectors
software-development, cloud-infrastructure, financial-services, health, government administration, manufacturing, telecoms
Target regions
EMEA, AMER, APAC
Detection rules
9
Indicators of compromise
15

How ServiceNow Scripted REST Resource Unauthenticated Access works

A Scripted REST Resource endpoint (/api/now/related_list_edit/create) on ServiceNow systems was configured with unauthenticated access (requires_authentication = false). Attackers from IP 51.159.98.241 successfully accessed backend functionality and executed table queries without authentication.

A critical misconfiguration in ServiceNow Scripted REST Resources allowed unauthenticated access to the /api/now/related_list_edit/create endpoint. The endpoint was configured with requires_authentication set to false, bypassing standard authentication and authorization controls. Security researchers and affected customers observed multiple successful access attempts originating from IP address 51.159.98.241 (OVH SA infrastructure, France). The attacker was able to execute backend queries and access related list data without providing valid credentials. Affected systems included customer instances running the Australia release and those with certain pre-release configuration changes. Because requests were processed without an authenticated user context, activity was logged under the Guest user account, complicating forensic analysis and attribution. ServiceNow indicated that successful table queries were observed in a subset of customer environments, suggesting potential data exfiltration. The vulnerability appears to stem from improper configuration of Scripted REST API endpoints rather than a traditional code vulnerability, though it represents a serious authentication bypass. Multiple customers were notified directly by ServiceNow regarding the scope of exposure.

MITRE ATT&CK techniques used in TL-2026-0980

Discovery

T1016 System Network Configuration Discovery; T1526 Cloud Service Discovery

Exfiltration

T1030 Data Transfer Size Limits; T1048 Exfiltration Over Alternative Protocol

Command and Control

T1071 Application Layer Protocol

Collection

T1074 Data Staged; T1213 Data from Information Repositories

Initial Access

T1133 External Remote Services; T1190 Exploit Public-Facing Application

Impact

T1485 Data Destruction; T1486 Data Encrypted for Impact

Privilege Escalation

T1548 Abuse Elevation Control Mechanism

Lateral Movement

T1550 Use Alternate Authentication Material

defense-impairment

T1556 Modify Authentication Process

defense-evasion

T1627.001 Geofencing

Affected products and versions in ServiceNow Scripted REST Resource Unauthenticated Access

  • ServiceNow — Now Platform
    Vulnerable versions: Australia release; Pre-release versions with configuration changes

Remediation for ServiceNow Scripted REST Resource Unauthenticated Access

Patches

  • Apply ServiceNow security patches for authentication validation
  • Update Scripted REST Resource configurations to enforce requires_authentication = true
  • Implement API access controls via ACLs on related_list_edit and similar endpoints

Immediate actions

  • Audit all Scripted REST Resource endpoints for requires_authentication = false configuration
  • Review API access logs for requests from IP 51.159.98.241 and similar external IPs
  • Check Guest user account activity logs for suspicious table queries
  • Block IP 51.159.98.241 and OVH IP ranges 51.159.0.0/16 at perimeter if not required
  • Enable request logging and monitoring on all REST API endpoints

Workarounds

  • Disable the /api/now/related_list_edit/create endpoint if not required
  • Restrict endpoint access via network firewall rules to known internal sources only
  • Implement reverse proxy authentication layer in front of ServiceNow

Longer-term hardening

  • Implement API gateway with authentication enforcement before ServiceNow instance
  • Deploy EDR with behavioral detection for suspicious database queries
  • Enforce API authentication requirements via policy in development/configuration controls
  • Implement network segmentation to restrict API access to known sources
  • Deploy UEBA to detect anomalous guest account activity
  • Implement query activity monitoring on backend tables
  • Review and audit all Scripted REST Resources and custom API endpoints

Weaknesses (CWE) in ServiceNow Scripted REST Resource Unauthenticated Access

CWE-306, CWE-862, CWE-863

Timeline of ServiceNow Scripted REST Resource Unauthenticated Access

  • ServiceNow confirms observing successful table queries in subset of customer environments; notifies affected customers directly
  • Multiple instances of successful access attempts from IP 51.159.98.241 confirmed by security researchers and affected customers
  • Security researchers publicly disclose /api/now/related_list_edit/create endpoint misconfiguration allowing unauthenticated access
  • Wiz Threat Intelligence publishes detailed analysis of ServiceNow unauthenticated access incident affecting Australia release and pre-release environments
  • Security researchers on Twitter/X begin analyzing incident scope and implications for ServiceNow customer base
  • Reddit r/servicenow community discusses incident; multiple customers report similar unauthenticated access attempts in their logs
  • Forensic analysis reveals requests logged under Guest user account, complicating attribution and forensic timeline reconstruction
  • ServiceNow provides guidance to customers on auditing Scripted REST Resource configurations and enforcing requires_authentication parameter

Sources cited for ServiceNow Scripted REST Resource Unauthenticated Access

Detection coverage for TL-2026-0980

As of 2026-06-09, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0980 across Splunk SPL, Microsoft KQL and Sigma, covering 15 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
15 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats