# ServiceNow Scripted REST Resource Unauthenticated Access - /api/now/related_list_edit/create

> A Scripted REST Resource endpoint (/api/now/related_list_edit/create) on ServiceNow systems was configured with unauthenticated access (requires_authentication = false). Attackers from IP 51.159.98.241 successfully accessed backend functionality and executed table queries without authentication.

- **Published:** 2026-06-09T00:00:00Z
- **Last reviewed:** 2026-06-09T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0980
- **ID:** TL-2026-0980
- **Severity:** CRITICAL
- **Category:** VULNERABILITY
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 15 (full data via the Threadlinqs MCP server — Purple tier)

## Description

A critical misconfiguration in ServiceNow Scripted REST Resources allowed unauthenticated access to the /api/now/related_list_edit/create endpoint. The endpoint was configured with requires_authentication set to false, bypassing standard authentication and authorization controls. Security researchers and affected customers observed multiple successful access attempts originating from IP address 51.159.98.241 (OVH SA infrastructure, France). The attacker was able to execute backend queries and access related list data without providing valid credentials. Affected systems included customer instances running the Australia release and those with certain pre-release configuration changes. Because requests were processed without an authenticated user context, activity was logged under the Guest user account, complicating forensic analysis and attribution. ServiceNow indicated that successful table queries were observed in a subset of customer environments, suggesting potential data exfiltration. The vulnerability appears to stem from improper configuration of Scripted REST API endpoints rather than a traditional code vulnerability, though it represents a serious authentication bypass. Multiple customers were notified directly by ServiceNow regarding the scope of exposure.

## MITRE ATT&CK

- T1190 Exploit Public-Facing Application
- T1133 External Remote Services
- T1556 Modify Authentication Process
- T1526 Cloud Service Discovery
- T1016 System Network Configuration Discovery
- T1213 Data from Information Repositories
- T1074 Data Staged
- T1627.001 Geofencing
- T1048 Exfiltration Over Alternative Protocol
- T1030 Data Transfer Size Limits
- T1071 Application Layer Protocol
- T1485 Data Destruction
- T1486 Data Encrypted for Impact
- T1548 Abuse Elevation Control Mechanism
- T1550 Use Alternate Authentication Material

## Sources

- [Wiz Threat Intelligence - ServiceNow Unauthenticated Access Incident](https://threats.wiz.io/all-incidents/servicenow-unauthenticated-access-incident)
- [Reddit r/servicenow - Community Discussion of Incident](https://www.reddit.com/r/servicenow/comments/1u0c45c/)
- [Twitter Security Researcher Coverage](https://x.com/i/status/2064391819962515853)
- [ServiceNow Scripted REST Resources Documentation](https://docs.servicenow.com/bundle/utah-api-reference/page/integrate/inbound-rest/concept/c_ScriptedRESTResources.html)
- [OWASP - Broken Authentication (A07:2021)](https://owasp.org/Top10/A07_2021-Broken_Authentication/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0980
