Worrying ServiceNow Security Error could let hackers steal private table data


  • An accident in ServiceNow -Thaglot checklists meant that users could access without accommodating all conditions
  • New controls were added to reduce the risk
  • Users are advised to review their tables and ACLs

An error in ServiceNow could have enabled threat actors to exfilter sensitive data from other user tables without ever knowing security experts warned.

The error traced as CVE-2025-3648 and got a severity of 8.2/10 (high) was called “Count (s) strike” and was discovered by security researchers Varonis.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top