A publicly accessible ServiceNow API endpoint required no authentication under certain conditions, allowing unauthorized access to sensitive enterprise data.
A misconfigured API endpoint in ServiceNow allowed unauthenticated access to customer tables — remediation was delayed by more than six weeks after the bug bounty report.