Servicenow’s security failure in concern could allow computer pirates to steal data from the private table


  • An accident in Servicenow’s access control lists meant that users could receive access, without complying with all conditions
  • New controls were added to mitigate risk
  • Users are recommended to review their tables and ACLs

A defect in Servicenow could have allowed the threat actors to exfiltrate confidential data from the tables of other users without them knowing, the security experts warned.

The defect, tracked as CVE-2025-3648 and administered a gravity score of 8.2/10 (high), was called “Strike (ER) Strike”, and was seen by Varonis security researchers.

Leave a Comment

Your email address will not be published. Required fields are marked *